Search CVE reports


Toggle filters

1191 – 1200 of 34709 results

Status is adjusted based on your filters.


CVE-2026-73492

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs...

1 affected package

ruby-loofah

Package 26.04 LTS
ruby-loofah Needs evaluation
Show less packages

CVE-2026-18727

Medium priority
Needs evaluation

A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6...

1 affected package

open-iscsi

Package 26.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18726

Medium priority
Needs evaluation

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control...

1 affected package

open-iscsi

Package 26.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-73491

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is...

1 affected package

ruby-loofah

Package 26.04 LTS
ruby-loofah Needs evaluation
Show less packages

CVE-2026-73490

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href...

1 affected package

ruby-loofah

Package 26.04 LTS
ruby-loofah Needs evaluation
Show less packages

CVE-2026-66898

Medium priority

Not in release

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-19654

Medium priority
Fixed

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No...

1 affected package

rsyslog

Package 26.04 LTS
rsyslog Fixed
Show less packages

CVE-2026-16033

Medium priority

Not in release

A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-73434

Medium priority
Needs evaluation

A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the...

1 affected package

gst-plugins-good1.0

Package 26.04 LTS
gst-plugins-good1.0 Needs evaluation
Show less packages

CVE-2026-73433

Medium priority
Needs evaluation

A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying...

1 affected package

gst-plugins-good1.0

Package 26.04 LTS
gst-plugins-good1.0 Needs evaluation
Show less packages