Search CVE reports


Toggle filters

361 – 370 of 40160 results

Status is adjusted based on your filters.


CVE-2026-88815

Medium priority
Needs evaluation

DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length of the SV to grok_number without...

1 affected package

libdbi-perl

Package 26.04 LTS
libdbi-perl Needs evaluation
Show less packages

CVE-2026-85644

Medium priority
Needs evaluation

XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator checks whether arguments are array references,...

1 affected package

libxs-parse-keyword-perl

Package 26.04 LTS
libxs-parse-keyword-perl Needs evaluation
Show less packages

CVE-2026-54160

Medium priority
Not affected

Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT...

1 affected package

nut

Package 26.04 LTS
nut Not affected
Show less packages

CVE-2026-97399

Medium priority
Needs evaluation

The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen...

2 affected packages

glibc, eglibc

Package 26.04 LTS
glibc Needs evaluation
eglibc Not in release
Show less packages

CVE-2026-101333

Medium priority

Not in release

A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An...

1 affected package

python-keycloak

Package 26.04 LTS
python-keycloak Not in release
Show less packages

CVE-2026-97335

Medium priority

Not in release

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-87799

Medium priority

Not in release

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-87798

Medium priority

Not in release

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-86335

Medium priority

Not in release

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages

CVE-2026-86334

Medium priority

Not in release

Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, 5.21.8, and 6.10 on all platforms allows a remote malicious or machine-in-the-middle image server to overwrite...

1 affected package

lxd

Package 26.04 LTS
lxd Not in release
Show less packages