Search CVE reports


Toggle filters

1211 – 1220 of 43788 results

Status is adjusted based on your filters.


CVE-2026-48553

Medium priority
Needs evaluation

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48552

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization,...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48551

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48550

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-19548

Medium priority
Needs evaluation

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original...

1 affected package

binutils

Package 24.04 LTS
binutils Needs evaluation
Show less packages

CVE-2026-66379

Medium priority

Not in release

An authenticated user may view private Puppet module metadata without repository read access.

1 affected package

puppet

Package 24.04 LTS
puppet Not in release
Show less packages

CVE-2026-18663

Medium priority
Needs evaluation

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation...

1 affected package

389-ds-base

Package 24.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-19566

Medium priority
Needs evaluation

Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to...

1 affected package

libnet-cidr-set-perl

Package 24.04 LTS
libnet-cidr-set-perl Needs evaluation
Show less packages

CVE-2026-9318

Medium priority
Needs evaluation

tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which...

1 affected package

python-tablib

Package 24.04 LTS
python-tablib Needs evaluation
Show less packages

CVE-2026-19588

Medium priority
Needs evaluation

Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

1 affected package

rlottie

Package 24.04 LTS
rlottie Needs evaluation
Show less packages