Search CVE reports


Toggle filters

21 – 30 of 49226 results

Status is adjusted based on your filters.


CVE-2026-82412

Medium priority
Needs evaluation

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept...

1 affected package

ntopng

Package 20.04 LTS
ntopng Needs evaluation
Show less packages

CVE-2026-80110

Medium priority
Needs evaluation

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission...

1 affected package

dogtag-pki

Package 20.04 LTS
dogtag-pki Needs evaluation
Show less packages

CVE-2026-74766

Medium priority
Needs evaluation

Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the...

1 affected package

libnet-idn-encode-perl

Package 20.04 LTS
libnet-idn-encode-perl Needs evaluation
Show less packages

CVE-2026-74765

Medium priority
Needs evaluation

Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a...

1 affected package

libnet-idn-encode-perl

Package 20.04 LTS
libnet-idn-encode-perl Needs evaluation
Show less packages

CVE-2026-68956

Medium priority
Needs evaluation

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-65634

Medium priority
Needs evaluation

Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder...

1 affected package

erlang

Package 20.04 LTS
erlang Needs evaluation
Show less packages

CVE-2026-62987

Medium priority
Needs evaluation

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the...

1 affected package

consul

Package 20.04 LTS
consul Needs evaluation
Show less packages

CVE-2026-61630

Medium priority
Needs evaluation

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches...

1 affected package

nginx

Package 20.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-61629

Medium priority
Needs evaluation

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and...

1 affected package

nginx

Package 20.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-61628

Medium priority
Needs evaluation

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions....

1 affected package

nginx

Package 20.04 LTS
nginx Needs evaluation
Show less packages