Search CVE reports


Toggle filters

61 – 70 of 42336 results

Status is adjusted based on your filters.


CVE-2026-52052

Medium priority

Not in release

[mg_tls_parse_cert_der pubkey BIT STRING length underflow -- OOB read]

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-52051

Medium priority

Not in release

[mg_tls_server_recv_hello session_id_len OOB read]

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-52050

Medium priority

Not in release

[precompute_slide_window NULL deref on OOM / more_comps NULL deref after failed calloc / bi_initialize / alloc NULL deref on OOM]

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-52048

Medium priority

Not in release

[MQTT v5 properties bounds check uses relative offset against absolute position]

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-52047

Medium priority

Not in release

[w5100_rx wraparound RX path copies n instead of r bytes]

1 affected package

mongoose

Package 24.04 LTS
mongoose Not in release
Show less packages

CVE-2026-48813

Medium priority
Needs evaluation

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI...

1 affected package

flawfinder

Package 24.04 LTS
flawfinder Needs evaluation
Show less packages

CVE-2026-48809

Medium priority
Needs evaluation

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked...

1 affected package

python-engineio

Package 24.04 LTS
python-engineio Needs evaluation
Show less packages

CVE-2026-48804

Medium priority
Needs evaluation

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the...

1 affected package

python-socketio

Package 24.04 LTS
python-socketio Needs evaluation
Show less packages

CVE-2026-48802

Medium priority
Needs evaluation

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the...

1 affected package

python-engineio

Package 24.04 LTS
python-engineio Needs evaluation
Show less packages

CVE-2026-48791

Medium priority
Needs evaluation

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio certificate. Version 2.1.0 re-added this...

1 affected package

golang-github-sigstore-sigstore

Package 24.04 LTS
golang-github-sigstore-sigstore Needs evaluation
Show less packages