Search CVE reports


Toggle filters

551 – 560 of 57488 results

Status is adjusted based on your filters.


CVE-2026-78807

Medium priority
Needs evaluation

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

1 affected package

wpa

Package 16.04 LTS
wpa Needs evaluation
Show less packages

CVE-2026-18495

Medium priority
Needs evaluation

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file,...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 16.04 LTS
tiff Needs evaluation
qtwebengine-opensource-src
texmaker Not affected
gdal Needs evaluation
neuron
Show less packages

CVE-2026-72710

Medium priority
Needs evaluation

SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-72709

Medium priority
Needs evaluation

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-72708

Medium priority
Needs evaluation

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word...

1 affected package

spip

Package 16.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-68497

Medium priority
Needs evaluation

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in...

1 affected package

jackson-databind

Package 16.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-77159

Medium priority
Needs evaluation

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm...

2 affected packages

libvirt, libvirt-hwe

Package 16.04 LTS
libvirt Needs evaluation
libvirt-hwe
Show less packages

CVE-2026-89044

Medium priority
Needs evaluation

(Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final th ...)

1 affected package

netty

Package 16.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-88924

Medium priority
Needs evaluation

(A flaw was found in the admin backend of gvfs. The privileged gvfsd-ad ...)

1 affected package

gvfs

Package 16.04 LTS
gvfs Needs evaluation
Show less packages

CVE-2026-88859

Medium priority
Needs evaluation

(A flaw was found in Evolution. A remote attacker can exploit this vuln ...)

1 affected package

evolution

Package 16.04 LTS
evolution Needs evaluation
Show less packages