Search CVE reports


Toggle filters

21 – 30 of 44563 results

Status is adjusted based on your filters.


CVE-2026-19518

Medium priority
Needs evaluation

Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.

1 affected package

rlottie

Package 20.04 LTS
rlottie Needs evaluation
Show less packages

CVE-2026-19517

Medium priority
Needs evaluation

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

1 affected package

rlottie

Package 20.04 LTS
rlottie Needs evaluation
Show less packages

CVE-2026-19411

Medium priority
Needs evaluation

A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.

3 affected packages

secureboot-db, shim-signed, shim

Package 20.04 LTS
secureboot-db Needs evaluation
shim-signed Needs evaluation
shim Needs evaluation
Show less packages

CVE-2026-19349

Medium priority
Needs evaluation

security update

1 affected package

lemonldap-ng

Package 20.04 LTS
lemonldap-ng Needs evaluation
Show less packages

CVE-2026-19135

Medium priority
Needs evaluation

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads...

1 affected package

horizon

Package 20.04 LTS
horizon Needs evaluation
Show less packages

CVE-2026-18728

Medium priority
Needs evaluation

A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local...

1 affected package

open-iscsi

Package 20.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18727

Medium priority
Needs evaluation

A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6...

1 affected package

open-iscsi

Package 20.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18726

Medium priority
Needs evaluation

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control...

1 affected package

open-iscsi

Package 20.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18710

Medium priority
Needs evaluation

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs...

1 affected package

mongo-java-driver

Package 20.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-18663

Medium priority
Needs evaluation

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages