Search CVE reports


Toggle filters

1311 – 1320 of 34566 results

Status is adjusted based on your filters.


CVE-2026-23411

High priority

Some fixes available 27 of 41

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from...

157 affected packages

linux-azure-4.15, linux-raspi-5.4, linux, linux-hwe, linux-hwe-5.4...

Package 24.04 LTS
linux-azure-4.15 Not in release
linux-raspi-5.4 Not in release
linux Fixed
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Not in release
linux-hwe-5.11 Not in release
linux-hwe-5.13 Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.19 Not in release
linux-hwe-6.2 Not in release
linux-hwe-6.5 Not in release
linux-hwe-6.8 Not in release
linux-hwe-6.11 Ignored
linux-hwe-6.14 Ignored
linux-hwe-6.17 Fixed
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Not in release
linux-allwinner-5.19 Not in release
linux-aws Fixed
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Not in release
linux-aws-5.11 Not in release
linux-aws-5.13 Not in release
linux-aws-5.15 Not in release
linux-aws-5.19 Not in release
linux-aws-6.2 Not in release
linux-aws-6.5 Not in release
linux-aws-6.8 Not in release
linux-aws-6.14 Ignored
linux-aws-6.17 Fixed
linux-aws-hwe Not in release
linux-azure Fixed
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Not in release
linux-azure-5.11 Not in release
linux-azure-5.13 Not in release
linux-azure-5.15 Not in release
linux-azure-5.19 Not in release
linux-azure-6.2 Not in release
linux-azure-6.5 Not in release
linux-azure-6.8 Not in release
linux-azure-6.11 Ignored
linux-azure-6.14 Vulnerable
linux-azure-6.17 Fixed
linux-azure-fde Needs evaluation
linux-azure-fde-5.15 Not in release
linux-azure-fde-5.19 Not in release
linux-azure-fde-6.2 Not in release
linux-azure-fde-6.8 Not in release
linux-azure-fde-6.14 Vulnerable
linux-azure-fde-6.17 Needs evaluation
linux-azure-nvidia Vulnerable
linux-azure-nvidia-6.14 Vulnerable
linux-bluefield Not in release
linux-azure-edge Not in release
linux-fips Fixed
linux-aws-fips Fixed
linux-azure-fips Fixed
linux-gcp-fips Fixed
linux-gcp Fixed
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Not in release
linux-gcp-5.11 Not in release
linux-gcp-5.13 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.19 Not in release
linux-gcp-6.2 Not in release
linux-gcp-6.5 Not in release
linux-gcp-6.8 Not in release
linux-gcp-6.11 Ignored
linux-gcp-6.14 Ignored
linux-gcp-6.17 Fixed
linux-gke Fixed
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Not in release
linux-gkeop Fixed
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Not in release
linux-ibm Fixed
linux-ibm-5.4 Not in release
linux-ibm-5.15 Not in release
linux-ibm-6.8 Not in release
linux-intel-5.13 Not in release
linux-intel-iotg Not in release
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-intel-iot-realtime Not in release
linux-lowlatency Fixed
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-5.19 Not in release
linux-lowlatency-hwe-6.2 Not in release
linux-lowlatency-hwe-6.5 Not in release
linux-lowlatency-hwe-6.8 Not in release
linux-lowlatency-hwe-6.11 Ignored
linux-nvidia Fixed
linux-nvidia-6.2 Not in release
linux-nvidia-6.5 Not in release
linux-nvidia-6.8 Not in release
linux-nvidia-6.11 Ignored
linux-nvidia-lowlatency Fixed
linux-nvidia-tegra Fixed
linux-nvidia-tegra-5.15 Not in release
linux-nvidia-tegra-igx Not in release
linux-oracle Fixed
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Not in release
linux-oracle-5.11 Not in release
linux-oracle-5.13 Not in release
linux-oracle-5.15 Not in release
linux-oracle-6.5 Not in release
linux-oracle-6.8 Not in release
linux-oracle-6.14 Ignored
linux-oracle-6.17 Fixed
linux-oem Not in release
linux-oem-5.6 Not in release
linux-oem-5.10 Not in release
linux-oem-5.13 Not in release
linux-oem-5.14 Not in release
linux-oem-5.17 Not in release
linux-oem-6.0 Not in release
linux-oem-6.1 Not in release
linux-oem-6.5 Not in release
linux-oem-6.8 Ignored
linux-oem-6.11 Ignored
linux-oem-6.14 Ignored
linux-oem-6.17 Fixed
linux-raspi Fixed
linux-raspi2 Not in release
linux-raspi-realtime Fixed
linux-realtime Fixed
linux-realtime-6.8 Not in release
linux-realtime-6.14 Ignored
linux-riscv Ignored
linux-riscv-5.8 Not in release
linux-riscv-5.11 Not in release
linux-riscv-5.15 Not in release
linux-riscv-5.19 Not in release
linux-riscv-6.5 Not in release
linux-riscv-6.8 Not in release
linux-riscv-6.14 Ignored
linux-riscv-6.17 Fixed
linux-starfive-5.19 Not in release
linux-starfive-6.2 Not in release
linux-starfive-6.5 Not in release
linux-xilinx Vulnerable
linux-xilinx-zynqmp Not in release
linux-realtime-6.17 Fixed
Show all 157 packages Show less packages

CVE-2026-34441

Medium priority
Needs evaluation

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses...

1 affected package

cpp-httplib

Package 24.04 LTS
cpp-httplib Needs evaluation
Show less packages

CVE-2026-4800

Medium priority
Needs evaluation

Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into...

1 affected package

node-lodash

Package 24.04 LTS
node-lodash Needs evaluation
Show less packages

CVE-2026-2950

Medium priority
Needs evaluation

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only...

1 affected package

node-lodash

Package 24.04 LTS
node-lodash Needs evaluation
Show less packages

CVE-2026-32726

Medium priority
Needs evaluation

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple...

1 affected package

scitokens-cpp

Package 24.04 LTS
scitokens-cpp Needs evaluation
Show less packages

CVE-2026-32725

Medium priority
Needs evaluation

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes...

1 affected package

scitokens-cpp

Package 24.04 LTS
scitokens-cpp Needs evaluation
Show less packages

CVE-2026-34235

Medium priority

Not in release

PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability...

1 affected package

pjproject

Package 24.04 LTS
pjproject Not in release
Show less packages

CVE-2026-34165

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identified in which a maliciously crafted .idx file can cause asymmetric...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS
golang-github-go-git-go-git Needs evaluation
Show less packages

CVE-2026-33762

Medium priority
Needs evaluation

go-git is an extensible git implementation library written in pure Go. Prior to version 5.17.1, go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded...

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS
golang-github-go-git-go-git Needs evaluation
Show less packages

CVE-2026-33276

Medium priority

Not in release

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in...

1 affected package

check-mk

Package 24.04 LTS
check-mk Not in release
Show less packages