Search CVE reports


Toggle filters

31 – 40 of 33493 results

Status is adjusted based on your filters.


CVE-2026-28389

Low priority
Vulnerable

Possible NULL dereference when processing CMS KeyAgreeRecipientInfo

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Vulnerable
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2026-28388

Low priority
Vulnerable

NULL Pointer Dereference When Processing a Delta CRL

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Vulnerable
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2026-28387

Low priority
Vulnerable

Potential use-after-free in DANE client code

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Vulnerable
openssl-fips Not in release
openssl1.0 Not in release
nodejs Not affected
edk2 Needs evaluation
Show less packages

CVE-2026-28386

Low priority
Not affected

Out-of-bounds read in AES-CFB-128 on X86-64 with AVX-512 support

5 affected packages

openssl, openssl-fips, openssl1.0, nodejs, edk2

Package 24.04 LTS
openssl Not affected
openssl-fips Not affected
openssl1.0 Not in release
nodejs Not affected
edk2 Not affected
Show less packages

CVE-2026-26263

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6.

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-26027

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store an XSS payload through the inventory endpoint. This vulnerability is fixed in 11.0.6.

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-26026

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administrator lead to RCE. This vulnerability is fixed in 11.0.6.

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-25932

Medium priority

Not in release

GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user can store an XSS payload in a supplier fields. This vulnerability is fixed in 10.0.24.

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-22675

Medium priority
Needs evaluation

OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript by submitting malicious User-Agent HTTP headers to the...

1 affected package

ocsinventory-server

Package 24.04 LTS
ocsinventory-server Needs evaluation
Show less packages

CVE-2026-5266

Medium priority
Needs evaluation

[Unknown description]

1 affected package

mediawiki

Package 24.04 LTS
mediawiki Needs evaluation
Show less packages