Search CVE reports


Toggle filters

1 – 10 of 31532 results

Status is adjusted based on your filters.


CVE-2026-24515

Medium priority
Needs evaluation

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS
expat Needs evaluation
apache2 Not affected
apr-util Not affected
cmake Not affected
ghostscript Not affected
texlive-bin Not affected
xmlrpc-c Needs evaluation
vnc4 Not in release
wbxml2 Needs evaluation
swish-e Needs evaluation
insighttoolkit4 Not in release
cadaver Needs evaluation
gdcm Not affected
ayttm Not in release
cableswig Not in release
coin3 Not affected
matanza Ignored
tdom Needs evaluation
vtk Not in release
smart Not in release
firefox Not affected
thunderbird Not affected
libxmltok Needs evaluation
Show all 23 packages Show less packages

CVE-2026-24137

Medium priority
Needs evaluation

sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the legacy TUF client (pkg/tuf/client.go) supports caching target files to disk. It constructs a filesystem path...

1 affected package

golang-github-sigstore-sigstore

Package 24.04 LTS
golang-github-sigstore-sigstore Needs evaluation
Show less packages

CVE-2026-24117

Medium priority

Not in release

Rekor is a software supply chain transparency log. In versions 1.4.3 and below, attackers can trigger SSRF to arbitrary internal services because /api/v1/index/retrieve supports retrieving a public key via user-provided URL. Since...

1 affected package

rekor

Package 24.04 LTS
rekor Not in release
Show less packages

CVE-2026-24049

Medium priority
Needs evaluation

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.46.1 and below, the unpack function is vulnerable to file permission modification through mishandling of file permissions after...

2 affected packages

wheel, python-pip

Package 24.04 LTS
wheel Needs evaluation
python-pip Needs evaluation
Show less packages

CVE-2026-24001

Medium priority
Needs evaluation

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, and 4.0.4, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause...

1 affected package

node-diff

Package 24.04 LTS
node-diff Needs evaluation
Show less packages

CVE-2026-23992

Medium priority
Needs evaluation

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which...

1 affected package

golang-github-theupdateframework-go-tuf

Package 24.04 LTS
golang-github-theupdateframework-go-tuf Needs evaluation
Show less packages

CVE-2026-23991

Medium priority
Needs evaluation

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF...

1 affected package

golang-github-theupdateframework-go-tuf

Package 24.04 LTS
golang-github-theupdateframework-go-tuf Needs evaluation
Show less packages

CVE-2026-23954

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic...

2 affected packages

incus, lxd

Package 24.04 LTS
incus Needs evaluation
lxd Not in release
Show less packages

CVE-2026-23953

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an...

2 affected packages

incus, lxd

Package 24.04 LTS
incus Needs evaluation
lxd Not in release
Show less packages

CVE-2026-23893

Medium priority
Needs evaluation

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations...

1 affected package

opencryptoki

Package 24.04 LTS
opencryptoki Needs evaluation
Show less packages