Search CVE reports


Toggle filters

1011 – 1020 of 38389 results

Status is adjusted based on your filters.


CVE-2026-34446

Medium priority
Needs evaluation

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path traversal, but completely misses...

1 affected package

onnx

Package 22.04 LTS
onnx Needs evaluation
Show less packages

CVE-2026-34445

Medium priority
Needs evaluation

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or...

1 affected package

onnx

Package 22.04 LTS
onnx Needs evaluation
Show less packages

CVE-2026-27489

Medium priority
Needs evaluation

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided...

1 affected package

onnx

Package 22.04 LTS
onnx Needs evaluation
Show less packages

CVE-2026-25834

Medium priority
Needs evaluation

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

1 affected package

mbedtls

Package 22.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-33990

Medium priority
Needs evaluation

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains an SSRF vulnerability in its OCI registry token exchange flow. When pulling a...

2 affected packages

docker.io, docker.io-app

Package 22.04 LTS
docker.io Needs evaluation
docker.io-app Needs evaluation
Show less packages

CVE-2026-35094

Medium priority
Not affected

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called,...

1 affected package

libinput

Package 22.04 LTS
libinput Not affected
Show less packages

CVE-2026-35093

Medium priority
Not affected

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized...

1 affected package

libinput

Package 22.04 LTS
libinput Not affected
Show less packages

CVE-2026-35092

Medium priority
Fixed

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the...

1 affected package

corosync

Package 22.04 LTS
corosync Fixed
Show less packages

CVE-2026-35091

Medium priority
Fixed

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol...

1 affected package

corosync

Package 22.04 LTS
corosync Fixed
Show less packages

CVE-2026-24096

Medium priority

Not in release

Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain...

1 affected package

check-mk

Package 22.04 LTS
check-mk Not in release
Show less packages