Search CVE reports


Toggle filters

91 – 100 of 40452 results

Status is adjusted based on your filters.


CVE-2026-104056

Medium priority
Needs evaluation

Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values...

1 affected package

python-authlib

Package 26.04 LTS
python-authlib Needs evaluation
Show less packages

CVE-2026-103885

Medium priority
Needs evaluation

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This...

1 affected package

apache-directory-api

Package 26.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103880

Medium priority
Needs evaluation

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for...

1 affected package

apache-directory-api

Package 26.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103878

Medium priority
Needs evaluation

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake...

1 affected package

apache-directory-api

Package 26.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103877

Medium priority
Needs evaluation

Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized...

1 affected package

apache-directory-api

Package 26.04 LTS
apache-directory-api Needs evaluation
Show less packages

CVE-2026-103631

Medium priority
Not affected

Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-103630

Medium priority
Not affected

Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-103629

Medium priority
Needs evaluation

Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

2 affected packages

chromium-browser, libskia

Package 26.04 LTS
chromium-browser Not affected
libskia Needs evaluation
Show less packages

CVE-2026-103628

Medium priority
Not affected

Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-103627

Medium priority
Not affected

Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

1 affected package

chromium-browser

Package 26.04 LTS
chromium-browser Not affected
Show less packages