Search CVE reports


Toggle filters

21 – 30 of 44355 results

Status is adjusted based on your filters.


CVE-2026-34191

Medium priority
Needs evaluation

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

1 affected package

apr-util

Package 20.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2026-32327

Medium priority
Needs evaluation

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses theĀ apr_xml_quote_elem() function. Users are recommended to upgrade to...

1 affected package

apr-util

Package 20.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2026-19079

Medium priority
Needs evaluation

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate...

1 affected package

policycoreutils

Package 20.04 LTS
policycoreutils Needs evaluation
Show less packages

CVE-2026-18938

Medium priority
Needs evaluation

A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to...

1 affected package

p11-kit

Package 20.04 LTS
p11-kit Needs evaluation
Show less packages

CVE-2026-18487

Medium priority
Needs evaluation

A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon...

1 affected package

epiphany-browser

Package 20.04 LTS
epiphany-browser Needs evaluation
Show less packages

CVE-2026-12261

Medium priority
Needs evaluation

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead...

1 affected package

nltk

Package 20.04 LTS
nltk Needs evaluation
Show less packages

CVE-2025-49506

Medium priority
Needs evaluation

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on...

1 affected package

apr-util

Package 20.04 LTS
apr-util Needs evaluation
Show less packages

CVE-2026-7867

Medium priority
Needs evaluation

security update

1 affected package

udisks2

Package 20.04 LTS
udisks2 Needs evaluation
Show less packages

CVE-2026-71313

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to...

1 affected package

rclone

Package 20.04 LTS
rclone Needs evaluation
Show less packages

CVE-2026-71312

Medium priority
Needs evaluation

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and...

1 affected package

rclone

Package 20.04 LTS
rclone Needs evaluation
Show less packages