Search CVE reports


Toggle filters

91 – 100 of 32959 results

Status is adjusted based on your filters.


CVE-2026-71311

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP filename encoding in backend/ftp/ftp.go can restore raw CR/LF immediately...

1 affected package

rclone

Package 26.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-71310

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper in lib/proxy/http.go parses proxy CONNECT responses...

1 affected package

rclone

Package 26.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-71309

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does not correctly reject URL paths beginning with ../...

1 affected package

rclone

Package 26.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-71227

Medium priority
Needs evaluation

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all()...

1 affected package

libkcapi

Package 26.04 LTS
libkcapi Needs evaluation
Show less packages

CVE-2026-71226

Medium priority
Needs evaluation

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

1 affected package

libkcapi

Package 26.04 LTS
libkcapi Needs evaluation
Show less packages

CVE-2026-71225

Medium priority
Needs evaluation

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses...

1 affected package

libkcapi

Package 26.04 LTS
libkcapi Needs evaluation
Show less packages

CVE-2026-67870

Medium priority
Needs evaluation

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri...

1 affected package

open62541

Package 26.04 LTS
open62541 Needs evaluation
Show less packages

CVE-2026-67869

Medium priority
Needs evaluation

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

1 affected package

open62541

Package 26.04 LTS
open62541 Needs evaluation
Show less packages

CVE-2026-67864

Medium priority
Needs evaluation

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component

1 affected package

open62541

Package 26.04 LTS
open62541 Needs evaluation
Show less packages

CVE-2026-67863

Medium priority
Needs evaluation

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes...

1 affected package

open62541

Package 26.04 LTS
open62541 Needs evaluation
Show less packages