Search CVE reports


Toggle filters

1481 – 1490 of 47443 results

Status is adjusted based on your filters.


CVE-2026-68006

Medium priority
Needs evaluation

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

1 affected package

puma

Package 24.04 LTS
puma Needs evaluation
Show less packages

CVE-2026-88050

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component....

1 affected package

tesseract

Package 24.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-88049

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left...

1 affected package

tesseract

Package 24.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-88048

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions....

1 affected package

tesseract

Package 24.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-88047

Medium priority
Needs evaluation

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract...

1 affected package

tesseract

Package 24.04 LTS
tesseract Needs evaluation
Show less packages

CVE-2026-88046

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list,...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-88045

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-88044

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-88018

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-88017

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in...

1 affected package

rclone

Package 24.04 LTS
rclone Needs evaluation
Show less packages