Search CVE reports


Toggle filters

21 – 30 of 82149 results


CVE-2026-92542

Medium priority
Needs evaluation

The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace...

2 affected packages

docker.io, docker.io-app

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
docker.io-app Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-92415

Medium priority
Needs evaluation

— Use of Externally-Controlled Input to Select Classes or Code vulnerability in Apache Jackrabbit's WebDAV/Davex client. A malicious WebDAV/DavEx server, or an attacker able to intercept the connection, can cause the client to...

1 affected package

jackrabbit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackrabbit Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-92414

Medium priority
Needs evaluation

: Session Fixation / Session Reuse across Users vulnerability in Apache Jackrabbit. Jackrabbit WebDAV server attaches a cached authenticated session on any Lock-Token/TransactionId/SubscriptionId/If-header field token match...

1 affected package

jackrabbit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jackrabbit Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-88964

Medium priority
Needs evaluation

[Unknown description]

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-84790

Medium priority
Needs evaluation

[Unknown description]

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-56851

Medium priority
Needs evaluation

The Nickname profile can panic with an out-of-bounds slice error when transforming crafted input into a short destination buffer.

2 affected packages

golang-golang-x-text, golang-x-text

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-text Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
golang-x-text Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-42532

Medium priority
Needs evaluation

A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a...

1 affected package

visidata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
visidata Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41958

Medium priority
Needs evaluation

A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a...

1 affected package

visidata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
visidata Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-107466

Medium priority
Needs evaluation

A flaw was found in flatpak-builder. This vulnerability allows an attacker to cause information disclosure by convincing a user or continuous integration (CI) system to process a crafted build manifest. By specifying local file...

1 affected package

flatpak-builder

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flatpak-builder Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-107363

Medium priority
Needs evaluation

In OpenStack Zaqar before 23.0.1, the WebSocket transport fails to bind the project identifier in subsequent requests to the project authenticated by the Keystone token. An authenticated user with a valid token for one project may...

1 affected package

zaqar

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
zaqar Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages