Search CVE reports


Toggle filters

2491 – 2500 of 46511 results

Status is adjusted based on your filters.


CVE-2026-54789

Medium priority
Needs evaluation

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte...

1 affected package

libapache2-mod-auth-openidc

Package 24.04 LTS
libapache2-mod-auth-openidc Needs evaluation
Show less packages

CVE-2026-49114

Medium priority
Needs evaluation

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()'...

1 affected package

onnx

Package 24.04 LTS
onnx Needs evaluation
Show less packages

CVE-2026-63343

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any...

1 affected package

incus

Package 24.04 LTS
incus Needs evaluation
Show less packages

CVE-2026-63125

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can...

1 affected package

incus

Package 24.04 LTS
incus Needs evaluation
Show less packages

CVE-2026-62941

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is...

1 affected package

incus

Package 24.04 LTS
incus Needs evaluation
Show less packages

CVE-2026-62940

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys...

1 affected package

incus

Package 24.04 LTS
incus Needs evaluation
Show less packages

CVE-2026-62867

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem...

1 affected package

incus

Package 24.04 LTS
incus Needs evaluation
Show less packages

CVE-2026-62313

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to create a non-isolated (shared...

1 affected package

incus

Package 24.04 LTS
incus Needs evaluation
Show less packages

CVE-2026-55622

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name...

2 affected packages

incus, lxd

Package 24.04 LTS
incus Needs evaluation
lxd Not in release
Show less packages

CVE-2026-55621

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the...

2 affected packages

incus, lxd

Package 24.04 LTS
incus Needs evaluation
lxd Not in release
Show less packages