Search CVE reports


Toggle filters

221 – 230 of 45072 results

Status is adjusted based on your filters.


CVE-2026-55584

Medium priority
Needs evaluation

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before...

1 affected package

phpsysinfo

Package 24.04 LTS
phpsysinfo Needs evaluation
Show less packages

CVE-2026-50624

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

qemu, qemu-hwe

Package 24.04 LTS
qemu Needs evaluation
qemu-hwe Not in release
Show less packages

CVE-2026-38822

Medium priority
Needs evaluation

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys....

1 affected package

opennds

Package 24.04 LTS
opennds Needs evaluation
Show less packages

CVE-2026-38821

Medium priority
Needs evaluation

A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code...

1 affected package

opennds

Package 24.04 LTS
opennds Needs evaluation
Show less packages

CVE-2026-38820

Medium priority
Needs evaluation

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.

1 affected package

opennds

Package 24.04 LTS
opennds Needs evaluation
Show less packages

CVE-2026-38819

Medium priority
Needs evaluation

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

1 affected package

opennds

Package 24.04 LTS
opennds Needs evaluation
Show less packages

CVE-2026-38350

Medium priority
Needs evaluation

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-38349

Medium priority
Needs evaluation

An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-38348

Medium priority
Needs evaluation

An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages

CVE-2026-38347

Medium priority
Needs evaluation

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

2 affected packages

ffmpeg, libav

Package 24.04 LTS
ffmpeg Needs evaluation
libav Not in release
Show less packages