Search CVE reports


Toggle filters

11 – 20 of 38218 results

Status is adjusted based on your filters.


CVE-2026-35538

Medium priority
Needs evaluation

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

1 affected package

roundcube

Package 20.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-35537

Medium priority
Needs evaluation

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

1 affected package

roundcube

Package 20.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-35536

Medium priority
Needs evaluation

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

1 affected package

python-tornado

Package 20.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-35535

Medium priority
Not affected

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

1 affected package

sudo

Package 20.04 LTS
sudo Not affected
Show less packages

CVE-2026-34990

Medium priority
Needs evaluation

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhost...

1 affected package

cups

Package 20.04 LTS
cups Needs evaluation
Show less packages

CVE-2026-34980

Medium priority
Needs evaluation

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job...

1 affected package

cups

Package 20.04 LTS
cups Needs evaluation
Show less packages

CVE-2026-34979

Medium priority
Needs evaluation

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings...

1 affected package

cups

Package 20.04 LTS
cups Needs evaluation
Show less packages

CVE-2026-34978

Medium priority
Needs evaluation

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache),...

1 affected package

cups

Package 20.04 LTS
cups Needs evaluation
Show less packages

CVE-2026-34933

Medium priority
Needs evaluation

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with...

1 affected package

avahi

Package 20.04 LTS
avahi Needs evaluation
Show less packages

CVE-2026-34095

Medium priority
Needs evaluation

[Unknown description]

1 affected package

mediawiki

Package 20.04 LTS
mediawiki Needs evaluation
Show less packages