Search CVE reports


Toggle filters

2281 – 2290 of 45973 results

Status is adjusted based on your filters.


CVE-2026-74934

Medium priority
Ignored

Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

9 affected packages

firefox, thunderbird, mozjs38, mozjs52, mozjs68...

Package 24.04 LTS
firefox Not affected
thunderbird Not affected
mozjs38 Not in release
mozjs52 Not in release
mozjs68 Not in release
mozjs78 Not in release
mozjs91 Not in release
mozjs102 Ignored
mozjs115 Ignored
Show all 9 packages Show less packages

CVE-2026-59781

Medium priority

Not in release

When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23938

Medium priority

Not in release

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23937

Medium priority

Not in release

The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23935

Medium priority

Not in release

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23934

Medium priority

Not in release

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23933

Medium priority

Not in release

In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23931

Medium priority

Not in release

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23930

Medium priority

Not in release

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23929

Medium priority

Not in release

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages