Search CVE reports


Toggle filters

121 – 130 of 39999 results

Status is adjusted based on your filters.


CVE-2026-62439

Medium priority
Needs evaluation

[Unknown description]

1 affected package

gimp

Package 26.04 LTS
gimp Needs evaluation
Show less packages

CVE-2026-61837

Medium priority
Needs evaluation

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET /bindings exposes full binding topology to any authenticated AMQP user without resource/management permission...

1 affected package

rabbitmq-server

Package 26.04 LTS
rabbitmq-server Needs evaluation
Show less packages

CVE-2026-55217

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authenticated user can create, update, or delete knowledge base comments and translations without the...

1 affected package

glpi

Package 26.04 LTS
glpi Not in release
Show less packages

CVE-2026-55214

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.6 until 11.0.8, an authenticated technician can store active markup in supplier website fields. Any user who opens the affected item's suppliers list triggers the...

1 affected package

glpi

Package 26.04 LTS
glpi Not in release
Show less packages

CVE-2026-54875

Low priority

Some fixes available 1 of 3

Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Vulnerable
edk2-hwe Vulnerable
Show less packages

CVE-2026-54872

Low priority

Some fixes available 1 of 3

Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves

6 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2, edk2-hwe

Package 26.04 LTS
openssl Fixed
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
edk2-hwe Needs evaluation
Show less packages

CVE-2026-54160

Medium priority
Needs evaluation

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT...

1 affected package

nut

Package 26.04 LTS
nut Needs evaluation
Show less packages

CVE-2026-53629

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with the READ right on logs can craft a URL for the history tab that injects attacker-controlled values into a...

1 affected package

glpi

Package 26.04 LTS
glpi Not in release
Show less packages

CVE-2026-53628

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable...

1 affected package

glpi

Package 26.04 LTS
glpi Not in release
Show less packages

CVE-2026-53627

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user can use the new API (v2) to perform update operations that the same user is normally forbidden to perform...

1 affected package

glpi

Package 26.04 LTS
glpi Not in release
Show less packages