Search CVE reports


Toggle filters

41 – 50 of 48501 results

Status is adjusted based on your filters.


CVE-2026-34486

Medium priority
Needs evaluation

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Needs evaluation
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-34483

Medium priority
Needs evaluation

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Needs evaluation
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-34179

Medium priority
Needs evaluation

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-34178

Medium priority
Needs evaluation

In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supplied tar archive but creates the instance from backup/container/backup.yaml, a separate file in the same...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-34177

Medium priority
Needs evaluation

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-33457

Medium priority
Needs evaluation

Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated user to inject arbitrary Livestatus commands via a crafted service name parameter due to insufficient...

1 affected package

check-mk

Package 16.04 LTS
check-mk Needs evaluation
Show less packages

CVE-2026-33456

Medium priority
Needs evaluation

Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with access to the notification test page to inject arbitrary Livestatus commands via a crafted service description.

1 affected package

check-mk

Package 16.04 LTS
check-mk Needs evaluation
Show less packages

CVE-2026-33455

Medium priority
Needs evaluation

Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.

1 affected package

check-mk

Package 16.04 LTS
check-mk Needs evaluation
Show less packages

CVE-2026-32990

Medium priority
Needs evaluation

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Needs evaluation
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9
tomcat10
tomcat11
Show less packages

CVE-2026-30479

Medium priority
Needs evaluation

A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted executable.

1 affected package

mapserver

Package 16.04 LTS
mapserver Needs evaluation
Show less packages