Search CVE reports


Toggle filters

1481 – 1490 of 46511 results

Status is adjusted based on your filters.


CVE-2026-82474

Medium priority
Needs evaluation

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through...

1 affected package

sudo

Package 24.04 LTS
sudo Needs evaluation
Show less packages

CVE-2026-82470

Medium priority

Not in release

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82469

Medium priority

Not in release

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82468

Medium priority

Not in release

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82467

Medium priority

Not in release

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82466

Medium priority

Not in release

Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls...

1 affected package

ruby-rodauth

Package 24.04 LTS
ruby-rodauth Not in release
Show less packages

CVE-2026-82481

Medium priority
Needs evaluation

The cohttp package before 6.3.0 for OCaml allows directory traversal.

1 affected package

ocaml-cohttp

Package 24.04 LTS
ocaml-cohttp Needs evaluation
Show less packages

CVE-2026-82455

Medium priority
Needs evaluation

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear...

6 affected packages

rubygems, ruby2.3, ruby2.5, ruby2.7, ruby3.0, jruby

Package 24.04 LTS
rubygems Needs evaluation
ruby2.3 Not in release
ruby2.5 Not in release
ruby2.7 Not in release
ruby3.0 Not in release
jruby Needs evaluation
Show less packages

CVE-2026-80725

High priority
Vulnerable

In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be...

168 affected packages

linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...

Package 24.04 LTS
linux Vulnerable
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Not in release
linux-hwe-5.11 Not in release
linux-hwe-5.13 Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.19 Not in release
linux-hwe-6.2 Not in release
linux-hwe-6.5 Not in release
linux-hwe-6.8 Not in release
linux-hwe-6.11 Ignored
linux-hwe-6.14 Ignored
linux-hwe-6.17 Vulnerable
linux-hwe-7.0 Not affected
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Not in release
linux-allwinner-5.19 Not in release
linux-aws Vulnerable
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Not in release
linux-aws-5.11 Not in release
linux-aws-5.13 Not in release
linux-aws-5.15 Not in release
linux-aws-5.19 Not in release
linux-aws-6.2 Not in release
linux-aws-6.5 Not in release
linux-aws-6.8 Not in release
linux-aws-6.14 Ignored
linux-aws-6.17 Ignored
linux-aws-7.0 Not affected
linux-aws-hwe Not in release
linux-azure Vulnerable
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Not in release
linux-azure-5.11 Not in release
linux-azure-5.13 Not in release
linux-azure-5.15 Not in release
linux-azure-5.19 Not in release
linux-azure-6.2 Not in release
linux-azure-6.5 Not in release
linux-azure-6.8 Not in release
linux-azure-6.11 Ignored
linux-azure-6.14 Ignored
linux-azure-6.17 Ignored
linux-azure-7.0 Not affected
linux-azure-fde Vulnerable
linux-azure-fde-5.15 Not in release
linux-azure-fde-5.19 Not in release
linux-azure-fde-6.2 Not in release
linux-azure-fde-6.8 Not in release
linux-azure-fde-6.14 Ignored
linux-azure-fde-6.17 Ignored
linux-azure-fde-7.0 Vulnerable
linux-azure-nvidia Vulnerable
linux-azure-nvidia-6.14 Ignored
linux-bluefield Not in release
linux-azure-edge Not in release
linux-fips Vulnerable
linux-aws-fips Vulnerable
linux-azure-fips Vulnerable
linux-gcp-fips Vulnerable
linux-gcp Vulnerable
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Not in release
linux-gcp-5.11 Not in release
linux-gcp-5.13 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.19 Not in release
linux-gcp-6.2 Not in release
linux-gcp-6.5 Not in release
linux-gcp-6.8 Not in release
linux-gcp-6.11 Ignored
linux-gcp-6.14 Ignored
linux-gcp-6.17 Ignored
linux-gcp-7.0 Not affected
linux-gke Vulnerable
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Not in release
linux-gkeop Vulnerable
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Not in release
linux-ibm Vulnerable
linux-ibm-5.4 Not in release
linux-ibm-5.15 Not in release
linux-ibm-6.8 Not in release
linux-intel-5.13 Not in release
linux-intel-iotg Not in release
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-intel-iot-realtime Not in release
linux-lowlatency Vulnerable
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-5.19 Not in release
linux-lowlatency-hwe-6.2 Not in release
linux-lowlatency-hwe-6.5 Not in release
linux-lowlatency-hwe-6.8 Not in release
linux-lowlatency-hwe-6.11 Ignored
linux-nvidia Vulnerable
linux-nvidia-6.2 Not in release
linux-nvidia-6.5 Not in release
linux-nvidia-6.8 Not in release
linux-nvidia-6.11 Ignored
linux-nvidia-6.17 Ignored
linux-nvidia-7.0 Not affected
linux-nvidia-bos Not in release
linux-nvidia-lowlatency Vulnerable
linux-nvidia-tegra Vulnerable
linux-nvidia-tegra-5.15 Not in release
linux-nvidia-tegra-igx Not in release
linux-oracle Vulnerable
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Not in release
linux-oracle-5.11 Not in release
linux-oracle-5.13 Not in release
linux-oracle-5.15 Not in release
linux-oracle-6.5 Not in release
linux-oracle-6.8 Not in release
linux-oracle-6.14 Ignored
linux-oracle-6.17 Ignored
linux-oracle-7.0 Not affected
linux-oem Not in release
linux-oem-5.6 Not in release
linux-oem-5.10 Not in release
linux-oem-5.13 Not in release
linux-oem-5.14 Not in release
linux-oem-5.17 Not in release
linux-oem-6.0 Not in release
linux-oem-6.1 Not in release
linux-oem-6.5 Not in release
linux-oem-6.8 Ignored
linux-oem-6.11 Ignored
linux-oem-6.14 Ignored
linux-oem-6.17 Vulnerable
linux-oem-7.0 Not in release
linux-raspi Vulnerable
linux-raspi2 Not in release
linux-raspi-5.4 Not in release
linux-raspi-realtime Vulnerable
linux-realtime Vulnerable
linux-realtime-6.8 Not in release
linux-realtime-6.14 Ignored
linux-riscv Ignored
linux-riscv-5.8 Not in release
linux-riscv-5.11 Not in release
linux-riscv-5.15 Not in release
linux-riscv-5.19 Not in release
linux-riscv-6.5 Not in release
linux-riscv-6.8 Not in release
linux-riscv-6.14 Ignored
linux-riscv-6.17 Ignored
linux-riscv-7.0 Not affected
linux-starfive-5.19 Not in release
linux-starfive-6.2 Not in release
linux-starfive-6.5 Not in release
linux-xilinx Vulnerable
linux-xilinx-zynqmp Not in release
linux-realtime-6.17 Ignored
Show all 168 packages Show less packages

CVE-2026-82343

Medium priority
Needs evaluation

A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds...

1 affected package

gimp

Package 24.04 LTS
gimp Needs evaluation
Show less packages