Search CVE reports


Toggle filters

81 – 90 of 29671 results

Status is adjusted based on your filters.


CVE-2026-28385

Medium priority

Not in release

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-9640

Medium priority

Not in release

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-9639

Medium priority

Not in release

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-12411

Medium priority

Not in release

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-0685

Medium priority
Needs evaluation

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.

1 affected package

genshi

Package 26.04 LTS
genshi Needs evaluation
Show less packages

CVE-2026-8286

Low priority
Vulnerable

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

1 affected package

curl

Package 26.04 LTS
curl Vulnerable
Show less packages

CVE-2026-57918

Medium priority
Needs evaluation

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the...

1 affected package

libnfs

Package 26.04 LTS
libnfs Needs evaluation
Show less packages

CVE-2026-6658

Medium priority
Needs evaluation

A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders...

1 affected package

nbconvert

Package 26.04 LTS
nbconvert Needs evaluation
Show less packages

CVE-2026-11625

Medium priority
Needs evaluation

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is...

1 affected package

libbytes-random-secure-perl

Package 26.04 LTS
libbytes-random-secure-perl Needs evaluation
Show less packages

CVE-2026-48936

Medium priority
Needs evaluation

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

1 affected package

nodejs

Package 26.04 LTS
nodejs Needs evaluation
Show less packages