Search CVE reports


Toggle filters

161 – 170 of 59631 results

Status is adjusted based on your filters.


CVE-2026-89102

Medium priority
Needs evaluation

In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. When a wolfSSL client enables OCSP stapling with the...

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-15442

Medium priority
Needs evaluation

In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead to a heap-use-after free. If an application ended up getting a...

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-94419

Medium priority
Needs evaluation

Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession()...

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-94418

Medium priority
Needs evaluation

Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged the signature result back only when the...

1 affected package

wolfssl

Package 16.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-100698

Medium priority
Needs evaluation

Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server...

1 affected package

adminer

Package 16.04 LTS
adminer Needs evaluation
Show less packages

CVE-2026-100697

Medium priority
Needs evaluation

Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker...

1 affected package

adminer

Package 16.04 LTS
adminer Needs evaluation
Show less packages

CVE-2026-100696

Medium priority
Needs evaluation

Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php...

1 affected package

adminer

Package 16.04 LTS
adminer Needs evaluation
Show less packages

CVE-2026-100695

Medium priority
Needs evaluation

Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute...

1 affected package

adminer

Package 16.04 LTS
adminer Needs evaluation
Show less packages

CVE-2026-100694

Medium priority
Needs evaluation

Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through...

1 affected package

hugo

Package 16.04 LTS
hugo Needs evaluation
Show less packages

CVE-2026-100693

Medium priority
Needs evaluation

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in...

1 affected package

hugo

Package 16.04 LTS
hugo Needs evaluation
Show less packages