Search CVE reports


Toggle filters

171 – 180 of 44948 results

Status is adjusted based on your filters.


CVE-2026-18726

Medium priority
Needs evaluation

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control...

1 affected package

open-iscsi

Package 20.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18710

Medium priority
Needs evaluation

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs...

1 affected package

mongo-java-driver

Package 20.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-18663

Medium priority
Needs evaluation

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation...

1 affected package

389-ds-base

Package 20.04 LTS
389-ds-base Needs evaluation
Show less packages

CVE-2026-18103

Medium priority
Needs evaluation

(A flaw was found in dhcp-server. A remote attacker with network access ...)

1 affected package

isc-dhcp

Package 20.04 LTS
isc-dhcp Needs evaluation
Show less packages

CVE-2026-16033

Medium priority
Needs evaluation

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths...

1 affected package

lxd

Package 20.04 LTS
lxd Needs evaluation
Show less packages

CVE-2026-15565

Medium priority
Needs evaluation

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service...

1 affected package

undertow

Package 20.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-15561

Medium priority
Needs evaluation

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments...

1 affected package

undertow

Package 20.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-15554

Medium priority
Needs evaluation

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT...

1 affected package

undertow

Package 20.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-14180

Medium priority
Needs evaluation

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store...

1 affected package

undertow

Package 20.04 LTS
undertow Needs evaluation
Show less packages

CVE-2026-12074

Medium priority
Needs evaluation

[Unknown description]

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages