Search CVE reports


Toggle filters

2291 – 2300 of 37984 results

Status is adjusted based on your filters.


CVE-2026-1539

Medium priority

Some fixes available 1 of 2

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTTP redirects, libsoup removes the Authorization header but does not remove the...

2 affected packages

libsoup2.4, libsoup3

Package 22.04 LTS
libsoup2.4 Vulnerable
libsoup3 Fixed
Show less packages

CVE-2026-1536

Medium priority

Some fixes available 1 of 2

A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when...

2 affected packages

libsoup2.4, libsoup3

Package 22.04 LTS
libsoup2.4 Vulnerable
libsoup3 Fixed
Show less packages

CVE-2026-23014

Medium priority
Ignored

In the Linux kernel, the following vulnerability has been resolved: perf: Ensure swevent hrtimer is properly destroyed With the change to hrtimer_try_to_cancel() in perf_swevent_cancel_hrtimer() it appears possible for the hrtimer...

157 affected packages

linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux, linux-hwe-5.11...

Package 22.04 LTS
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Not in release
linux Not affected
linux-hwe-5.11 Not in release
linux-hwe-5.13 Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.19 Ignored
linux-hwe-6.2 Ignored
linux-hwe-6.5 Ignored
linux-hwe-6.8 Not affected
linux-hwe-6.11 Not in release
linux-hwe-6.14 Not in release
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Not affected
linux-allwinner-5.19 Ignored
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Not in release
linux-aws-5.11 Not in release
linux-aws Not affected
linux-aws-5.13 Not in release
linux-aws-5.15 Not in release
linux-aws-5.19 Ignored
linux-aws-6.2 Ignored
linux-aws-6.5 Ignored
linux-aws-6.8 Not affected
linux-aws-6.14 Not in release
linux-aws-hwe Not in release
linux-azure Not affected
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Not in release
linux-azure-5.11 Not in release
linux-azure-5.13 Not in release
linux-azure-5.15 Not in release
linux-azure-5.19 Ignored
linux-azure-6.2 Ignored
linux-azure-6.5 Ignored
linux-azure-6.8 Not affected
linux-azure-6.11 Not in release
linux-azure-6.14 Not in release
linux-azure-fde Not affected
linux-azure-fde-5.15 Not in release
linux-azure-fde-5.19 Ignored
linux-azure-fde-6.2 Ignored
linux-azure-fde-6.8 Not affected
linux-azure-fde-6.14 Not in release
linux-azure-nvidia Not in release
linux-azure-nvidia-6.14 Not in release
linux-bluefield Not in release
linux-azure-edge Not in release
linux-fips Not affected
linux-aws-fips Not affected
linux-azure-fips Not affected
linux-gcp-fips Not affected
linux-gcp Not affected
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Not in release
linux-gcp-5.11 Not in release
linux-gcp-5.13 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.19 Ignored
linux-gcp-6.2 Ignored
linux-gcp-6.5 Ignored
linux-gcp-6.8 Not affected
linux-gcp-6.11 Not in release
linux-gcp-6.14 Not in release
linux-gke Not affected
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Not in release
linux-gkeop Not affected
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Not in release
linux-ibm Not affected
linux-ibm-5.4 Not in release
linux-ibm-5.15 Not in release
linux-ibm-6.8 Not affected
linux-intel-5.13 Not in release
linux-intel-iotg Not affected
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-intel-iot-realtime Not affected
linux-lowlatency Not affected
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-5.19 Ignored
linux-lowlatency-hwe-6.2 Ignored
linux-lowlatency-hwe-6.5 Ignored
linux-lowlatency-hwe-6.8 Not affected
linux-lowlatency-hwe-6.11 Not in release
linux-nvidia Not affected
linux-nvidia-6.2 Ignored
linux-nvidia-6.5 Ignored
linux-nvidia-6.8 Not affected
linux-nvidia-6.11 Not in release
linux-nvidia-lowlatency Not in release
linux-nvidia-tegra Not affected
linux-nvidia-tegra-5.15 Not in release
linux-nvidia-tegra-igx Not affected
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Not in release
linux-oracle-5.11 Not in release
linux-oracle-5.13 Not in release
linux-oracle-5.15 Not in release
linux-oracle-6.5 Ignored
linux-oracle-6.8 Not affected
linux-oracle-6.14 Not in release
linux-oem Not in release
linux-oem-5.6 Not in release
linux-oem-5.10 Not in release
linux-oem-5.13 Not in release
linux-oem-5.14 Not in release
linux-oem-5.17 Ignored
linux-oem-6.0 Ignored
linux-oem-6.1 Ignored
linux-oem-6.5 Ignored
linux-oem-6.8 Not in release
linux-oem-6.11 Not in release
linux-oem-6.14 Not in release
linux-oem-6.17 Not in release
linux-raspi2 Not in release
linux-raspi-5.4 Not in release
linux-raspi-realtime Not in release
linux-realtime-6.8 Not affected
linux-realtime-6.14 Not in release
linux-riscv Ignored
linux-riscv-5.8 Not in release
linux-riscv-5.11 Not in release
linux-riscv-5.15 Not in release
linux-riscv-5.19 Ignored
linux-riscv-6.5 Ignored
linux-riscv-6.8 Not affected
linux-riscv-6.14 Not in release
linux-starfive-5.19 Ignored
linux-starfive-6.2 Ignored
linux-starfive-6.5 Ignored
linux-xilinx Not in release
linux-xilinx-zynqmp Not affected
linux-oracle Not affected
linux-raspi Not affected
linux-realtime Not affected
linux-aws-6.17 Not in release
linux-gcp-6.17 Not in release
linux-hwe-6.17 Not in release
linux-oracle-6.17 Not in release
linux-riscv-6.17 Not in release
linux-azure-6.17 Not in release
linux-azure-fde-6.17 Not in release
linux-realtime-6.17 Not in release
Show all 157 packages Show less packages

CVE-2026-1237

Low priority

Not in release

Vulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to update database records can mint an invalid macaroon that is incorrectly validated by the...

1 affected package

juju

Package 22.04 LTS
juju Not in release
Show less packages

CVE-2020-36986

Medium priority

Not in release

Prey 1.9.6 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the CronService to insert malicious code that...

1 affected package

prey

Package 22.04 LTS
prey Not in release
Show less packages

CVE-2026-24842

Medium priority
Needs evaluation

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows...

1 affected package

node-tar

Package 22.04 LTS
node-tar Needs evaluation
Show less packages

CVE-2026-23553

Medium priority
Needs evaluation

In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the previous vCPU to run. While safe for Xen's isolation between vCPUs, this prevents the guest kernel correctly...

1 affected package

xen

Package 22.04 LTS
xen Needs evaluation
Show less packages

CVE-2025-58150

Medium priority
Needs evaluation

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest controlled data, of guest controllable size. That size can be larger than the...

1 affected package

xen

Package 22.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-24765

Medium priority
Needs evaluation

PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution....

1 affected package

phpunit

Package 22.04 LTS
phpunit Needs evaluation
Show less packages

CVE-2026-24747

Medium priority
Needs evaluation

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with...

1 affected package

pytorch

Package 22.04 LTS
pytorch Needs evaluation
Show less packages