Search CVE reports


Toggle filters

2521 – 2530 of 59015 results

Status is adjusted based on your filters.


CVE-2026-84837

Medium priority
Needs evaluation

A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in...

1 affected package

rpm

Package 16.04 LTS
rpm Needs evaluation
Show less packages

CVE-2026-78410

Medium priority
Needs evaluation

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor...

1 affected package

util-linux

Package 16.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-78409

Medium priority
Needs evaluation

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep...

1 affected package

util-linux

Package 16.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-78408

Medium priority
Needs evaluation

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations...

1 affected package

util-linux

Package 16.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-53683

Medium priority
Needs evaluation

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is...

1 affected package

freeipa

Package 16.04 LTS
freeipa Needs evaluation
Show less packages

CVE-2026-81928

Medium priority
Needs evaluation

Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs a message by re-encoding it, and removes TSIG records...

1 affected package

libnet-dns-perl

Package 16.04 LTS
libnet-dns-perl Needs evaluation
Show less packages

CVE-2026-16658

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

ansible, ansible-core

Package 16.04 LTS
ansible Needs evaluation
ansible-core —
Show less packages

CVE-2026-84372

Medium priority
Needs evaluation

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer...

1 affected package

php-nrk-predis

Package 16.04 LTS
php-nrk-predis Needs evaluation
Show less packages

CVE-2026-84366

Medium priority
Needs evaluation

Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP...

11 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Needs evaluation
python3.4 —
python3.5 Needs evaluation
python3.6 —
python3.7 —
python3.8 —
python3.9 —
python3.10 —
python3.11 —
python3.12 —
python3.14 —
Show all 11 packages Show less packages

CVE-2026-84361

Medium priority
Needs evaluation

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and...

1 affected package

composer

Package 16.04 LTS
composer Needs evaluation
Show less packages