Search CVE reports


Toggle filters

41 – 50 of 47986 results

Status is adjusted based on your filters.


CVE-2026-19624

Medium priority
Needs evaluation

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged...

1 affected package

network-manager-l2tp

Package 20.04 LTS
network-manager-l2tp Needs evaluation
Show less packages

CVE-2026-82049

Medium priority
Needs evaluation

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or...

12 affected packages

pypy3, python2.7, python3.4, python3.5, python3.6...

Package 20.04 LTS
pypy3 Needs evaluation
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Needs evaluation
python3.9 Needs evaluation
python3.10
python3.11
python3.12
python3.14
Show all 12 packages Show less packages

CVE-2026-82035

Medium priority
Needs evaluation

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a...

1 affected package

pymupdf

Package 20.04 LTS
pymupdf Needs evaluation
Show less packages

CVE-2026-55847

Medium priority
Needs evaluation

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and...

1 affected package

allure

Package 20.04 LTS
allure Needs evaluation
Show less packages

CVE-2026-55846

Medium priority
Needs evaluation

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer()...

1 affected package

allure

Package 20.04 LTS
allure Needs evaluation
Show less packages

CVE-2026-53495

Medium priority
Needs evaluation

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine...

3 affected packages

containerd, containerd-app, containerd-stable

Package 20.04 LTS
containerd Needs evaluation
containerd-app Needs evaluation
containerd-stable
Show less packages

CVE-2026-55073

Medium priority
Needs evaluation

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed...

1 affected package

weasyprint

Package 20.04 LTS
weasyprint Needs evaluation
Show less packages

CVE-2026-71198

Medium priority
Needs evaluation

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply...

1 affected package

glance

Package 20.04 LTS
glance Needs evaluation
Show less packages

CVE-2026-25832

Medium priority
Needs evaluation

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

1 affected package

mbedtls

Package 20.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2023-34854

Medium priority
Needs evaluation

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

1 affected package

hoteldruid

Package 20.04 LTS
hoteldruid Needs evaluation
Show less packages