Search CVE reports


Toggle filters

51 – 60 of 37641 results

Status is adjusted based on your filters.


CVE-2026-28808

Medium priority
Needs evaluation

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside...

1 affected package

erlang

Package 22.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-22666

Medium priority

Not in release

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect...

1 affected package

dolibarr

Package 22.04 LTS
dolibarr Not in release
Show less packages

CVE-2025-39666

Medium priority

Not in release

Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating...

1 affected package

check-mk

Package 22.04 LTS
check-mk Not in release
Show less packages

CVE-2026-31842

Medium priority
Needs evaluation

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the...

1 affected package

tinyproxy

Package 22.04 LTS
tinyproxy Needs evaluation
Show less packages

CVE-2026-4878

Medium priority
Needs evaluation

[Address a potential TOCTOU race condition in cap_set_file()]

1 affected package

libcap2

Package 22.04 LTS
libcap2 Needs evaluation
Show less packages

CVE-2026-34197

Medium priority
Needs evaluation

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web...

1 affected package

activemq

Package 22.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-33227

Medium priority
Needs evaluation

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All. In two instances (when creating a Stomp consumer and also browsing messages in the...

1 affected package

activemq

Package 22.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-31790

Medium priority
Fixed

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 22.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-31789

Low priority
Fixed

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker...

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 22.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-28810

Medium priority
Needs evaluation

Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction...

1 affected package

erlang

Package 22.04 LTS
erlang Needs evaluation
Show less packages