Search CVE reports


Toggle filters

201 – 210 of 48104 results

Status is adjusted based on your filters.


CVE-2026-59168

Medium priority
Needs evaluation

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go...

1 affected package

dasel

Package 24.04 LTS
dasel Needs evaluation
Show less packages

CVE-2026-82412

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept...

1 affected package

ntopng

Package 24.04 LTS
ntopng Needs evaluation
Show less packages

CVE-2026-94301

Medium priority
Needs evaluation

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was...

1 affected package

mina2

Package 24.04 LTS
mina2 Needs evaluation
Show less packages

CVE-2026-94184

Medium priority
Needs evaluation

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past...

1 affected package

fetchmail

Package 24.04 LTS
fetchmail Needs evaluation
Show less packages

CVE-2026-80110

Medium priority

Not in release

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission...

1 affected package

dogtag-pki

Package 24.04 LTS
dogtag-pki Not in release
Show less packages

CVE-2026-61630

Medium priority
Not affected

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches...

1 affected package

nginx

Package 24.04 LTS
nginx Not affected
Show less packages

CVE-2026-61629

Medium priority
Not affected

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and...

1 affected package

nginx

Package 24.04 LTS
nginx Not affected
Show less packages

CVE-2026-61628

Medium priority
Not affected

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions....

1 affected package

nginx

Package 24.04 LTS
nginx Not affected
Show less packages

CVE-2026-55567

Medium priority
Not affected

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that...

1 affected package

bleachbit

Package 24.04 LTS
bleachbit Not affected
Show less packages

CVE-2026-88807

Medium priority
Needs evaluation

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

1 affected package

libxrender

Package 24.04 LTS
libxrender Needs evaluation
Show less packages