Search CVE reports


Toggle filters

1291 – 1300 of 46188 results

Status is adjusted based on your filters.


CVE-2026-71193

Medium priority
Needs evaluation

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone...

1 affected package

designate

Package 20.04 LTS
designate Needs evaluation
Show less packages

CVE-2026-73500

Medium priority
Needs evaluation

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send...

1 affected package

etcd

Package 20.04 LTS
etcd Needs evaluation
Show less packages

CVE-2026-73499

Medium priority
Needs evaluation

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey()...

1 affected package

etcd

Package 20.04 LTS
etcd Needs evaluation
Show less packages

CVE-2026-73492

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs...

1 affected package

ruby-loofah

Package 20.04 LTS
ruby-loofah Needs evaluation
Show less packages

CVE-2026-18727

Medium priority
Needs evaluation

A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6...

1 affected package

open-iscsi

Package 20.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18726

Medium priority
Needs evaluation

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control...

1 affected package

open-iscsi

Package 20.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-73491

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is...

1 affected package

ruby-loofah

Package 20.04 LTS
ruby-loofah Needs evaluation
Show less packages

CVE-2026-73490

Medium priority
Needs evaluation

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href...

1 affected package

ruby-loofah

Package 20.04 LTS
ruby-loofah Needs evaluation
Show less packages

CVE-2026-66898

Medium priority
Needs evaluation

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume...

1 affected package

lxd

Package 20.04 LTS
lxd Needs evaluation
Show less packages

CVE-2026-19654

Medium priority
Needs evaluation

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No...

1 affected package

rsyslog

Package 20.04 LTS
rsyslog Needs evaluation
Show less packages