Search CVE reports


Toggle filters

251 – 260 of 40159 results

Status is adjusted based on your filters.


CVE-2026-101902

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-101901

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-101900

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-101898

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request...

1 affected package

node-axios

Package 26.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-88816

Medium priority
Needs evaluation

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the key name without stringifying it first. When...

1 affected package

libdbi-perl

Package 26.04 LTS
libdbi-perl Needs evaluation
Show less packages

CVE-2026-88815

Medium priority
Needs evaluation

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without...

1 affected package

libdbi-perl

Package 26.04 LTS
libdbi-perl Needs evaluation
Show less packages

CVE-2026-85644

Medium priority
Needs evaluation

XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references,...

1 affected package

libxs-parse-keyword-perl

Package 26.04 LTS
libxs-parse-keyword-perl Needs evaluation
Show less packages

CVE-2026-54160

Medium priority
Needs evaluation

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT...

1 affected package

nut

Package 26.04 LTS
nut Needs evaluation
Show less packages

CVE-2026-97399

Medium priority
Needs evaluation

The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen...

2 affected packages

glibc, eglibc

Package 26.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages

CVE-2026-101333

Medium priority

Not in release

A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An...

1 affected package

python-keycloak

Package 26.04 LTS
python-keycloak Not in release
Show less packages