Search CVE reports


Toggle filters

1 – 10 of 36635 results

Status is adjusted based on your filters.


CVE-2026-24515

Medium priority
Needs evaluation

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 20.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Needs evaluation
cadaver Needs evaluation
gdcm Not affected
ayttm
cableswig
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk
smart
firefox
thunderbird
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-24049

Medium priority
Needs evaluation

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.46.1 and below, the unpack function is vulnerable to file permission modification through mishandling of file permissions after...

2 affected packages

wheel, python-pip

Package 20.04 LTS
wheel Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-24001

Medium priority
Needs evaluation

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, and 4.0.4, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause...

1 affected package

node-diff

Package 20.04 LTS
node-diff Needs evaluation
Show less packages

CVE-2026-23954

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-23953

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an...

2 affected packages

incus, lxd

Package 20.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-23893

Medium priority
Needs evaluation

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations...

1 affected package

opencryptoki

Package 20.04 LTS
opencryptoki Needs evaluation
Show less packages

CVE-2026-22977

Medium priority
Vulnerable

In the Linux kernel, the following vulnerability has been resolved: net: sock: fix hardened usercopy panic in sock_recv_errqueue skbuff_fclone_cache was created without defining a usercopy region, [1] unlike skbuff_head_cache...

149 affected packages

linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...

Package 20.04 LTS
linux Vulnerable
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Ignored
linux-hwe-5.11 Ignored
linux-hwe-5.13 Ignored
linux-hwe-5.15 Vulnerable
linux-hwe-5.19 Not in release
linux-hwe-6.2 Not in release
linux-hwe-6.5 Not in release
linux-hwe-6.8 Not in release
linux-hwe-6.11 Not in release
linux-hwe-6.14 Not in release
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Vulnerable
linux-allwinner-5.19 Not in release
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Ignored
linux-aws-5.11 Ignored
linux-aws-5.13 Ignored
linux-aws-5.15 Vulnerable
linux-aws-5.19 Not in release
linux-aws-6.2 Not in release
linux-aws-6.5 Not in release
linux-aws-6.8 Not in release
linux-aws-6.14 Not in release
linux-aws-hwe Not in release
linux-azure Vulnerable
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Ignored
linux-azure-5.11 Ignored
linux-azure-5.13 Ignored
linux-azure-5.15 Vulnerable
linux-azure-5.19 Not in release
linux-azure-6.2 Not in release
linux-azure-6.5 Not in release
linux-azure-6.8 Not in release
linux-azure-6.11 Not in release
linux-azure-6.14 Not in release
linux-azure-fde Ignored
linux-azure-fde-5.15 Not affected
linux-azure-fde-5.19 Not in release
linux-azure-fde-6.2 Not in release
linux-azure-fde-6.8 Not in release
linux-azure-fde-6.14 Not in release
linux-azure-nvidia Not in release
linux-azure-nvidia-6.14 Not in release
linux-bluefield Vulnerable
linux-azure-edge Not in release
linux-fips Vulnerable
linux-aws-fips Vulnerable
linux-azure-fips Vulnerable
linux-gcp-fips Vulnerable
linux-gcp Vulnerable
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Ignored
linux-gcp-5.11 Ignored
linux-gcp-5.13 Ignored
linux-gcp-5.15 Vulnerable
linux-gcp-5.19 Not in release
linux-gcp-6.2 Not in release
linux-gcp-6.5 Not in release
linux-gcp-6.8 Not in release
linux-gcp-6.11 Not in release
linux-gcp-6.14 Not in release
linux-gke Ignored
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Ignored
linux-gkeop Ignored
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Ignored
linux-ibm Vulnerable
linux-ibm-5.4 Not in release
linux-ibm-5.15 Vulnerable
linux-ibm-6.8 Not in release
linux-intel-5.13 Ignored
linux-intel-iotg Not in release
linux-intel-iotg-5.15 Vulnerable
linux-iot Vulnerable
linux-intel-iot-realtime Not in release
linux-lowlatency Not in release
linux-lowlatency-hwe-5.15 Vulnerable
linux-lowlatency-hwe-5.19 Not in release
linux-lowlatency-hwe-6.2 Not in release
linux-lowlatency-hwe-6.5 Not in release
linux-lowlatency-hwe-6.8 Not in release
linux-lowlatency-hwe-6.11 Not in release
linux-nvidia Not in release
linux-nvidia-6.2 Not in release
linux-nvidia-6.5 Not in release
linux-nvidia-6.8 Not in release
linux-nvidia-6.11 Not in release
linux-nvidia-lowlatency Not in release
linux-nvidia-tegra Not in release
linux-nvidia-tegra-5.15 Vulnerable
linux-nvidia-tegra-igx Not in release
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Ignored
linux-oracle-5.11 Ignored
linux-oracle-5.13 Ignored
linux-oracle-5.15 Vulnerable
linux-oracle-6.5 Not in release
linux-oracle-6.8 Not in release
linux-oracle-6.14 Not in release
linux-oem Not in release
linux-oem-5.6 Ignored
linux-oem-5.10 Ignored
linux-oem-5.13 Ignored
linux-oem-5.14 Ignored
linux-oem-5.17 Not in release
linux-oem-6.0 Not in release
linux-oem-6.1 Not in release
linux-oem-6.5 Not in release
linux-oem-6.8 Not in release
linux-oem-6.11 Not in release
linux-oem-6.14 Not in release
linux-oem-6.17 Not in release
linux-raspi2 Ignored
linux-raspi-5.4 Not in release
linux-raspi-realtime Not in release
linux-realtime-6.8 Not in release
linux-realtime-6.14 Not in release
linux-riscv Ignored
linux-riscv-5.8 Ignored
linux-riscv-5.11 Ignored
linux-riscv-5.15 Vulnerable
linux-riscv-5.19 Not in release
linux-riscv-6.5 Not in release
linux-riscv-6.8 Not in release
linux-riscv-6.14 Not in release
linux-starfive-5.19 Not in release
linux-starfive-6.2 Not in release
linux-starfive-6.5 Not in release
linux-xilinx Not in release
linux-xilinx-zynqmp Vulnerable
linux-aws Vulnerable
linux-oracle Vulnerable
linux-raspi Vulnerable
linux-realtime Not in release
Show all 149 packages Show less packages

CVE-2026-1225

Medium priority
Needs evaluation

ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising...

1 affected package

logback

Package 20.04 LTS
logback Needs evaluation
Show less packages

CVE-2026-1200

Medium priority
Needs evaluation

[Unknown description]

1 affected package

liblivemedia

Package 20.04 LTS
liblivemedia Needs evaluation
Show less packages

CVE-2026-0775

Medium priority
Needs evaluation

npm cli Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of npm cli. An attacker must first obtain the ability to...

1 affected package

npm

Package 20.04 LTS
npm Needs evaluation
Show less packages