Search CVE reports


Toggle filters

11 – 20 of 32830 results

Status is adjusted based on your filters.


CVE-2026-4738

Medium priority
Needs evaluation

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with program files inftree9.C‎. This issue affects gdal:...

1 affected package

gdal

Package 24.04 LTS
gdal Needs evaluation
Show less packages

CVE-2026-33306

Medium priority

Not in release

bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. ...

1 affected package

bcrypt

Package 24.04 LTS
bcrypt Not in release
Show less packages

CVE-2026-33298

Medium priority

Not in release

llama.cpp is an inference of several LLM models in C/C++. Prior to b7824, an integer overflow vulnerability in the `ggml_nbytes` function allows an attacker to bypass memory validation by crafting a GGUF file with specific tensor...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-33202

Medium priority
Needs evaluation

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without...

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-33195

Medium priority
Needs evaluation

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path...

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-33176

Medium priority
Needs evaluation

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Support number helpers accept strings containing...

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-33174

Medium priority
Needs evaluation

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when serving files through Active Storage's proxy delivery mode, the proxy controller loads the...

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-33173

Medium priority
Needs evaluation

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `DirectUploadsController` accepts arbitrary metadata from the client and persists it on the blob....

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-33170

Medium priority
Needs evaluation

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `SafeBuffer#%` does not propagate the `@html_unsafe` flag to the newly...

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages

CVE-2026-33169

Medium priority
Needs evaluation

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a lookahead-based regular expression with `gsub!` to insert thousands delimiters....

1 affected package

rails

Package 24.04 LTS
rails Needs evaluation
Show less packages