Search CVE reports


Toggle filters

101 – 110 of 38750 results

Status is adjusted based on your filters.


CVE-2026-40941

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31.

1 affected package

cacti

Package 24.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-40084

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing arbitrary file read. This vulnerability occurs in...

1 affected package

cacti

Package 24.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-40083

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 of managers.php, the application assigns...

1 affected package

cacti

Package 24.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-40082

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful...

1 affected package

cacti

Package 24.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-40080

Medium priority
Needs evaluation

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the...

1 affected package

cacti

Package 24.04 LTS
cacti Needs evaluation
Show less packages

CVE-2026-8720

Medium priority
Needs evaluation

wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the supplied key is longer than the BLAKE2 block size...

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-7532

Medium priority
Needs evaluation

iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-7511

Medium priority
Needs evaluation

PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-6331

Medium priority
Needs evaluation

HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the supplied signature length was only checked as...

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages

CVE-2026-6330

Medium priority
Needs evaluation

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The constant-time comparison effectively...

1 affected package

wolfssl

Package 24.04 LTS
wolfssl Needs evaluation
Show less packages