Search CVE reports


Toggle filters

331 – 340 of 42336 results

Status is adjusted based on your filters.


CVE-2026-61632

Medium priority
Needs evaluation

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images...

2 affected packages

markdown, python-markdown

Package 24.04 LTS
markdown Needs evaluation
python-markdown Needs evaluation
Show less packages

CVE-2026-50159

Medium priority

Not in release

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated...

1 affected package

node-mermaid

Package 24.04 LTS
node-mermaid Not in release
Show less packages

CVE-2026-43632

Medium priority

Not in release

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens)...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-43631

Medium priority

Not in release

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-43630

Medium priority

Not in release

llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore path that allows attackers with write access to the slot save directory to read memory past the end of the...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-43629

Medium priority

Not in release

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() function computes write size without overflow checking, allowing attackers with write...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-43628

Medium priority

Not in release

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated attackers to trigger a heap buffer underflow by sending a crafted HTTP request...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-43627

Medium priority

Not in release

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in malloc() calls can wrap past INT32_MAX when computing allocation sizes. Attackers...

1 affected package

llama.cpp

Package 24.04 LTS
llama.cpp Not in release
Show less packages

CVE-2026-19177

Medium priority
Not affected

Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML...

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages

CVE-2026-19176

Medium priority
Not affected

Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

1 affected package

chromium-browser

Package 24.04 LTS
chromium-browser Not affected
Show less packages