Search CVE reports


Toggle filters

191 – 200 of 52206 results

Status is adjusted based on your filters.


CVE-2016-15059

Medium priority
Not affected

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns,...

1 affected package

libnet-idn-encode-perl

Package 22.04 LTS
libnet-idn-encode-perl Not affected
Show less packages

CVE-2026-79079

Medium priority
Needs evaluation

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

1 affected package

xiphos

Package 22.04 LTS
xiphos Needs evaluation
Show less packages

CVE-2026-94572

Medium priority
Needs evaluation

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the...

1 affected package

octavia

Package 22.04 LTS
octavia Needs evaluation
Show less packages

CVE-2026-94571

Medium priority
Needs evaluation

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before...

1 affected package

octavia

Package 22.04 LTS
octavia Needs evaluation
Show less packages

CVE-2026-79318

Medium priority

Not in release

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

1 affected package

web2py

Package 22.04 LTS
web2py Not in release
Show less packages

CVE-2026-93012

Medium priority
Needs evaluation

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every...

1 affected package

libemail-sender-perl

Package 22.04 LTS
libemail-sender-perl Needs evaluation
Show less packages

CVE-2026-84990

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua...

1 affected package

ntopng

Package 22.04 LTS
ntopng Needs evaluation
Show less packages

CVE-2026-83621

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls...

1 affected package

ntopng

Package 22.04 LTS
ntopng Needs evaluation
Show less packages

CVE-2026-62987

Medium priority
Needs evaluation

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the...

1 affected package

consul

Package 22.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-62866

Medium priority

Not in release

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then...

1 affected package

dasel

Package 22.04 LTS
dasel Not in release
Show less packages