Search CVE reports


Toggle filters

301 – 310 of 36372 results

Status is adjusted based on your filters.


CVE-2026-21722

Medium priority

Not in release

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard,...

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2025-41117

Medium priority

Not in release

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources...

1 affected package

grafana

Package 22.04 LTS
grafana Not in release
Show less packages

CVE-2026-2327

Medium priority
Needs evaluation

Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of...

1 affected package

node-markdown-it

Package 22.04 LTS
node-markdown-it Needs evaluation
Show less packages

CVE-2026-2391

Medium priority
Needs evaluation

### Summary The `arrayLimit` option in qs does not enforce limits for comma-separated values when `comma: true` is enabled, allowing attackers to cause denial-of-service via memory exhaustion. This is a bypass of the array limit...

1 affected package

node-qs

Package 22.04 LTS
node-qs Needs evaluation
Show less packages

CVE-2026-26081

Medium priority
Not affected

crash via INITIAL packet for the NEW_TOKEN format

1 affected package

haproxy

Package 22.04 LTS
haproxy Not affected
Show less packages

CVE-2026-26080

Medium priority
Not affected

crash in parsing frame type

1 affected package

haproxy

Package 22.04 LTS
haproxy Not affected
Show less packages

CVE-2026-1669

Medium priority

Not in release

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted...

1 affected package

keras

Package 22.04 LTS
keras Not in release
Show less packages

CVE-2026-26158

Medium priority
Needs evaluation

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar...

1 affected package

busybox

Package 22.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-26157

Medium priority
Needs evaluation

A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the...

1 affected package

busybox

Package 22.04 LTS
busybox Needs evaluation
Show less packages

CVE-2026-26014

Medium priority

Not in release

Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1.0 use random nonce generation with AES GCM ciphers, which makes it easier for remote attackers to obtain the...

2 affected packages

golang-github-pion-dtls-v3, golang-github-pion-dtls.v2

Package 22.04 LTS
golang-github-pion-dtls-v3 Not in release
golang-github-pion-dtls.v2 Not in release
Show less packages