Search CVE reports


Toggle filters

21 – 30 of 36570 results

Status is adjusted based on your filters.


CVE-2025-12801

Medium priority
Needs evaluation

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it...

155 affected packages

linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...

Package 22.04 LTS
linux Needs evaluation
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Not in release
linux-hwe-5.11 Not in release
linux-hwe-5.13 Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.19 Ignored
linux-hwe-6.2 Ignored
linux-hwe-6.5 Ignored
linux-hwe-6.8 Needs evaluation
linux-hwe-6.11 Not in release
linux-hwe-6.14 Not in release
linux-hwe-6.17 Not in release
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Needs evaluation
linux-allwinner-5.19 Ignored
linux-aws Needs evaluation
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Not in release
linux-aws-5.11 Not in release
linux-aws-5.13 Not in release
linux-aws-5.15 Not in release
linux-aws-5.19 Ignored
linux-aws-6.2 Ignored
linux-aws-6.5 Ignored
linux-aws-6.8 Needs evaluation
linux-aws-6.14 Not in release
linux-aws-6.17 Not in release
linux-aws-hwe Not in release
linux-azure Needs evaluation
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Not in release
linux-azure-5.11 Not in release
linux-azure-5.13 Not in release
linux-azure-5.15 Not in release
linux-azure-5.19 Ignored
linux-azure-6.2 Ignored
linux-azure-6.5 Ignored
linux-azure-6.8 Needs evaluation
linux-azure-6.11 Not in release
linux-azure-6.14 Not in release
linux-azure-fde Needs evaluation
linux-azure-fde-5.15 Not in release
linux-azure-fde-5.19 Ignored
linux-azure-fde-6.2 Ignored
linux-azure-fde-6.8 Needs evaluation
linux-azure-fde-6.14 Not in release
linux-azure-nvidia Not in release
linux-azure-nvidia-6.14 Not in release
linux-bluefield Not in release
linux-azure-edge Not in release
linux-fips Not in release
linux-aws-fips Not in release
linux-azure-fips Not in release
linux-gcp-fips Not in release
linux-gcp Needs evaluation
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Not in release
linux-gcp-5.11 Not in release
linux-gcp-5.13 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.19 Ignored
linux-gcp-6.2 Ignored
linux-gcp-6.5 Ignored
linux-gcp-6.8 Needs evaluation
linux-gcp-6.11 Not in release
linux-gcp-6.14 Not in release
linux-gcp-6.17 Not in release
linux-gke Needs evaluation
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Not in release
linux-gkeop Needs evaluation
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Not in release
linux-ibm Needs evaluation
linux-ibm-5.4 Not in release
linux-ibm-5.15 Not in release
linux-ibm-6.8 Needs evaluation
linux-intel-5.13 Not in release
linux-intel-iotg Needs evaluation
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-intel-iot-realtime Ignored
linux-lowlatency Needs evaluation
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-5.19 Ignored
linux-lowlatency-hwe-6.2 Ignored
linux-lowlatency-hwe-6.5 Ignored
linux-lowlatency-hwe-6.8 Needs evaluation
linux-lowlatency-hwe-6.11 Not in release
linux-nvidia Needs evaluation
linux-nvidia-6.2 Ignored
linux-nvidia-6.5 Ignored
linux-nvidia-6.8 Needs evaluation
linux-nvidia-6.11 Not in release
linux-nvidia-lowlatency Not in release
linux-nvidia-tegra Needs evaluation
linux-nvidia-tegra-5.15 Not in release
linux-nvidia-tegra-igx Needs evaluation
linux-oracle Needs evaluation
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Not in release
linux-oracle-5.11 Not in release
linux-oracle-5.13 Not in release
linux-oracle-5.15 Not in release
linux-oracle-6.5 Ignored
linux-oracle-6.8 Needs evaluation
linux-oracle-6.14 Not in release
linux-oracle-6.17 Not in release
linux-oem Not in release
linux-oem-5.6 Not in release
linux-oem-5.10 Not in release
linux-oem-5.13 Not in release
linux-oem-5.14 Not in release
linux-oem-5.17 Ignored
linux-oem-6.0 Ignored
linux-oem-6.1 Ignored
linux-oem-6.5 Ignored
linux-oem-6.8 Not in release
linux-oem-6.11 Not in release
linux-oem-6.14 Not in release
linux-oem-6.17 Not in release
linux-raspi Needs evaluation
linux-raspi2 Not in release
linux-raspi-5.4 Not in release
linux-raspi-realtime Not in release
linux-realtime Ignored
linux-realtime-6.8 Not in release
linux-realtime-6.14 Not in release
linux-riscv Ignored
linux-riscv-5.8 Not in release
linux-riscv-5.11 Not in release
linux-riscv-5.15 Not in release
linux-riscv-5.19 Ignored
linux-riscv-6.5 Ignored
linux-riscv-6.8 Needs evaluation
linux-riscv-6.14 Not in release
linux-riscv-6.17 Not in release
linux-starfive-5.19 Ignored
linux-starfive-6.2 Ignored
linux-starfive-6.5 Ignored
linux-xilinx Not in release
linux-xilinx-zynqmp Needs evaluation
nfs-utils Needs evaluation
Show all 155 packages Show less packages

CVE-2025-11143

Medium priority
Needs evaluation

The Jetty URI parser has some key differences to other common parsers when evaluating invalid or unusual URIs. Differential parsing of URIs in systems using multiple components may result in security by-pass. For example...

2 affected packages

jetty12, jetty9

Package 22.04 LTS
jetty12 Not in release
jetty9 Needs evaluation
Show less packages

CVE-2026-27446

Medium priority
Needs evaluation

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core...

1 affected package

activemq

Package 22.04 LTS
activemq Needs evaluation
Show less packages

CVE-2025-66168

Medium priority
Needs evaluation

Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining...

1 affected package

activemq

Package 22.04 LTS
activemq Needs evaluation
Show less packages

CVE-2026-21619

Medium priority
Needs evaluation

2 affected packages

rebar3, erlang-hex

Package 22.04 LTS
rebar3 Needs evaluation
erlang-hex Not in release
Show less packages

CVE-2026-27932

Medium priority

Not in release

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a resource exhaustion vulnerability in joserfc allows an unauthenticated attacker to...

1 affected package

joserfc

Package 22.04 LTS
joserfc Not in release
Show less packages

CVE-2026-27622

Medium priority
Needs evaluation

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated...

1 affected package

openexr

Package 22.04 LTS
openexr Needs evaluation
Show less packages

CVE-2026-27601

Medium priority
Needs evaluation

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. Under very specific conditions, detailed below, an attacker could exploit this in...

1 affected package

ruby-rails-assets-underscore

Package 22.04 LTS
ruby-rails-assets-underscore Needs evaluation
Show less packages

CVE-2026-29022

Medium priority
Needs evaluation

dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV...

5 affected packages

dosbox-x, faudio, octave-ltfat, qtads, roc-toolkit

Package 22.04 LTS
dosbox-x Not in release
faudio Needs evaluation
octave-ltfat Needs evaluation
qtads Needs evaluation
roc-toolkit Not in release
Show less packages

CVE-2026-0540

Medium priority
Needs evaluation

DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 729097f, contain a cross-site scripting vulnerability that allows attackers to bypass attribute sanitization by exploiting five missing rawtext elements...

1 affected package

node-dompurify

Package 22.04 LTS
node-dompurify Needs evaluation
Show less packages