Search CVE reports


Toggle filters

1041 – 1050 of 38389 results

Status is adjusted based on your filters.


CVE-2026-33276

Medium priority

Not in release

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in...

1 affected package

check-mk

Package 22.04 LTS
check-mk Not in release
Show less packages

CVE-2026-20915

Medium priority

Not in release

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will...

1 affected package

check-mk

Package 22.04 LTS
check-mk Not in release
Show less packages

CVE-2026-34155

Medium priority
Needs evaluation

RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' format exceeding a payload size of 2 GiB cause an integer overflow which results in a signature which covers only...

1 affected package

rauc

Package 22.04 LTS
rauc Needs evaluation
Show less packages

CVE-2026-3308

Medium priority
Needs evaluation

An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap...

1 affected package

mupdf

Package 22.04 LTS
mupdf Needs evaluation
Show less packages

CVE-2026-27854

Medium priority
Needs evaluation

An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of...

1 affected package

dnsdist

Package 22.04 LTS
dnsdist Needs evaluation
Show less packages

CVE-2026-27853

Medium priority
Needs evaluation

An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. In some cases the rewritten packet...

1 affected package

dnsdist

Package 22.04 LTS
dnsdist Needs evaluation
Show less packages

CVE-2026-24030

Medium priority
Needs evaluation

An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available...

1 affected package

dnsdist

Package 22.04 LTS
dnsdist Needs evaluation
Show less packages

CVE-2026-24029

Medium priority
Needs evaluation

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the...

1 affected package

dnsdist

Package 22.04 LTS
dnsdist Needs evaluation
Show less packages

CVE-2026-24028

Medium priority
Needs evaluation

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a...

1 affected package

dnsdist

Package 22.04 LTS
dnsdist Needs evaluation
Show less packages

CVE-2026-0397

Medium priority
Needs evaluation

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration...

1 affected package

dnsdist

Package 22.04 LTS
dnsdist Needs evaluation
Show less packages