Search CVE reports


Toggle filters

1 – 10 of 32739 results

Status is adjusted based on your filters.


CVE-2026-4407

Medium priority
Needs evaluation

Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color spaces.

2 affected packages

xpdf, ipe

Package 24.04 LTS
xpdf Needs evaluation
ipe Needs evaluation
Show less packages

CVE-2026-32722

Medium priority

Not in release

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled...

1 affected package

python-memray

Package 24.04 LTS
python-memray Not in release
Show less packages

CVE-2026-32700

Medium priority
Needs evaluation

Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise...

1 affected package

ruby-devise

Package 24.04 LTS
ruby-devise Needs evaluation
Show less packages

CVE-2026-32694

Medium priority

Not in release

In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret owner relies exclusively on a predictable XID of the secret to verify ownership. This allows a malicious...

1 affected package

juju

Package 24.04 LTS
juju Not in release
Show less packages

CVE-2026-32693

Medium priority

Not in release

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the...

1 affected package

juju

Package 24.04 LTS
juju Not in release
Show less packages

CVE-2026-32692

Medium priority

Not in release

An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18 allows an authenticated unit agent to perform unauthorized updates to secret revisions. With sufficient...

1 affected package

juju

Package 24.04 LTS
juju Not in release
Show less packages

CVE-2026-32691

Medium priority

Not in release

A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit agent to claim ownership of a newly initialized secret. Between generating a Juju Secret ID and creating the...

1 affected package

juju

Package 24.04 LTS
juju Not in release
Show less packages

CVE-2026-32636

Medium priority
Needs evaluation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9.13-42, the NewXMLTree method contains a bug that could result in a crash due to an out of write bounds of a...

1 affected package

imagemagick

Package 24.04 LTS
imagemagick Needs evaluation
Show less packages

CVE-2026-32634

Medium priority
Needs evaluation

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glances stores both the Zeroconf-advertised server name and the discovered IP address for dynamic servers, but later...

1 affected package

glances

Package 24.04 LTS
glances Needs evaluation
Show less packages

CVE-2026-32633

Medium priority
Needs evaluation

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, the `/api/4/serverslist` endpoint returns raw server objects from `GlancesServersList.get_servers_list()`. Those...

1 affected package

glances

Package 24.04 LTS
glances Needs evaluation
Show less packages