Search CVE reports


Toggle filters

101 – 110 of 33257 results

Status is adjusted based on your filters.


CVE-2026-19411

Medium priority
Needs evaluation

A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.

3 affected packages

secureboot-db, shim-signed, shim

Package 26.04 LTS
secureboot-db Needs evaluation
shim-signed Needs evaluation
shim Needs evaluation
Show less packages

CVE-2026-19349

Medium priority
Needs evaluation

security update

1 affected package

lemonldap-ng

Package 26.04 LTS
lemonldap-ng Needs evaluation
Show less packages

CVE-2026-19135

Medium priority
Needs evaluation

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads...

1 affected package

horizon

Package 26.04 LTS
horizon Needs evaluation
Show less packages

CVE-2026-18728

Medium priority
Needs evaluation

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local...

1 affected package

open-iscsi

Package 26.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18727

Medium priority
Needs evaluation

A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6...

1 affected package

open-iscsi

Package 26.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18726

Medium priority
Needs evaluation

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control...

1 affected package

open-iscsi

Package 26.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18710

Medium priority
Needs evaluation

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs...

1 affected package

mongo-java-driver

Package 26.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-18663

Medium priority
Needs evaluation

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation...

1 affected package

389-ds-base

Package 26.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-18103

Medium priority
Needs evaluation

(A flaw was found in dhcp-server. A remote attacker with network access ...)

1 affected package

isc-dhcp

Package 26.04 LTS
isc-dhcp Needs evaluation
Show less packages

CVE-2026-16033

Medium priority

Not in release

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages