Search CVE reports


Toggle filters

1421 – 1430 of 39027 results

Status is adjusted based on your filters.


CVE-2026-87268

Medium priority
Needs evaluation

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the...

1 affected package

virtualbox

Package 26.04 LTS
virtualbox Needs evaluation
Show less packages

CVE-2026-87267

Medium priority
Needs evaluation

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with network...

1 affected package

virtualbox

Package 26.04 LTS
virtualbox Needs evaluation
Show less packages

CVE-2026-61544

Medium priority
Needs evaluation

libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS...

1 affected package

rust-libp2p-identity

Package 26.04 LTS
rust-libp2p-identity Needs evaluation
Show less packages

CVE-2026-19774

Medium priority
Needs evaluation

BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain...

1 affected package

bluez

Package 26.04 LTS
bluez Needs evaluation
Show less packages

CVE-2026-19773

Medium priority
Needs evaluation

libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of...

1 affected package

libwebsockets

Package 26.04 LTS
libwebsockets Needs evaluation
Show less packages

CVE-2026-85234

Medium priority
Needs evaluation

A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function....

1 affected package

tftp-hpa

Package 26.04 LTS
tftp-hpa Needs evaluation
Show less packages

CVE-2026-48785

Medium priority
Needs evaluation

Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also...

1 affected package

apptainer

Package 26.04 LTS
apptainer Needs evaluation
Show less packages

CVE-2026-91992

Medium priority
Needs evaluation

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests...

1 affected package

python-tornado

Package 26.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-91991

Medium priority
Needs evaluation

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed...

1 affected package

python-tornado

Package 26.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-91990

Medium priority
Needs evaluation

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to...

1 affected package

python-tornado

Package 26.04 LTS
python-tornado Needs evaluation
Show less packages