Search CVE reports


Toggle filters

1971 – 1980 of 45973 results

Status is adjusted based on your filters.


CVE-2026-48749

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version...

2 affected packages

incus, lxd

Package 24.04 LTS
incus Needs evaluation
lxd Not in release
Show less packages

CVE-2026-47753

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with...

1 affected package

incus

Package 24.04 LTS
incus Needs evaluation
Show less packages

CVE-2026-77806

Medium priority
Needs evaluation

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by...

1 affected package

spip

Package 24.04 LTS
spip Needs evaluation
Show less packages

CVE-2026-15576

Medium priority

Not in release

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the...

1 affected package

check-mk

Package 24.04 LTS
check-mk Not in release
Show less packages

CVE-2026-77651

Medium priority
Needs evaluation

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

1 affected package

rust-arrayref

Package 24.04 LTS
rust-arrayref Needs evaluation
Show less packages

CVE-2026-77650

Medium priority

Not in release

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary...

1 affected package

rust-append-only-vec

Package 24.04 LTS
rust-append-only-vec Not in release
Show less packages

CVE-2026-64787

Medium priority

Some fixes available 1 of 2

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-64783

Medium priority

Some fixes available 1 of 2

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-64757

Medium priority

Some fixes available 1 of 2

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing...

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages

CVE-2026-64730

Medium priority

Some fixes available 1 of 2

The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.

5 affected packages

webkitgtk, webkit2gtk, qtwebkit-source, qtwebkit-opensource-src, wpewebkit

Package 24.04 LTS
webkitgtk Not in release
webkit2gtk Fixed
qtwebkit-source Not in release
qtwebkit-opensource-src Ignored
wpewebkit Not in release
Show less packages