Search CVE reports


Toggle filters

131 – 140 of 38797 results

Status is adjusted based on your filters.


CVE-2026-12411

Medium priority

Not in release

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when...

1 affected package

lxd

Package 24.04 LTS
lxd Not in release
Show less packages

CVE-2026-0685

Medium priority
Needs evaluation

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

1 affected package

genshi

Package 24.04 LTS
genshi Needs evaluation
Show less packages

CVE-2026-8286

Low priority
Vulnerable

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

1 affected package

curl

Package 24.04 LTS
curl Vulnerable
Show less packages

CVE-2026-57918

Medium priority
Not affected

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the...

1 affected package

libnfs

Package 24.04 LTS
libnfs Not affected
Show less packages

CVE-2026-6658

Medium priority
Needs evaluation

A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders...

1 affected package

nbconvert

Package 24.04 LTS
nbconvert Needs evaluation
Show less packages

CVE-2026-11625

Medium priority
Needs evaluation

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is...

1 affected package

libbytes-random-secure-perl

Package 24.04 LTS
libbytes-random-secure-perl Needs evaluation
Show less packages

CVE-2026-48936

Medium priority
Needs evaluation

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-48935

Medium priority
Needs evaluation

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js...

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-48934

Medium priority
Needs evaluation

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages

CVE-2026-48933

Medium priority
Needs evaluation

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

1 affected package

nodejs

Package 24.04 LTS
nodejs Needs evaluation
Show less packages