Search CVE reports


Toggle filters

1661 – 1670 of 46017 results

Status is adjusted based on your filters.


CVE-2026-15816

Medium priority
Needs evaluation

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the...

1 affected package

dracut

Package 20.04 LTS
dracut Needs evaluation
Show less packages

CVE-2026-64638

Medium priority
Needs evaluation

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE...

1 affected package

wordpress

Package 20.04 LTS
wordpress Needs evaluation
Show less packages

CVE-2026-61477

Medium priority
Vulnerable

An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are...

1 affected package

libvirt

Package 20.04 LTS
libvirt Vulnerable
Show less packages

CVE-2026-52682

Medium priority
Needs evaluation

[A crafted DNS packet can cause increased memory and CPU consumption]

3 affected packages

dnsdist, pdns, pdns-recursor

Package 20.04 LTS
dnsdist Needs evaluation
pdns Needs evaluation
pdns-recursor Needs evaluation
Show less packages

CVE-2026-19079

Medium priority
Needs evaluation

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate...

1 affected package

policycoreutils

Package 20.04 LTS
policycoreutils Needs evaluation
Show less packages

CVE-2026-18938

Medium priority
Needs evaluation

A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to...

1 affected package

p11-kit

Package 20.04 LTS
p11-kit Needs evaluation
Show less packages

CVE-2026-12261

Medium priority
Needs evaluation

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-71554

Medium priority
Needs evaluation

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to the consuming application. Where...

1 affected package

python-h2

Package 20.04 LTS
python-h2 Needs evaluation
Show less packages

CVE-2026-71498

Medium priority
Needs evaluation

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end...

1 affected package

node-re2

Package 20.04 LTS
node-re2 Needs evaluation
Show less packages

CVE-2026-71497

Medium priority
Needs evaluation

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior...

1 affected package

jsoup

Package 20.04 LTS
jsoup Needs evaluation
Show less packages