Search CVE reports


Toggle filters

1271 – 1280 of 39385 results

Status is adjusted based on your filters.


CVE-2026-35538

Medium priority
Needs evaluation

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.

1 affected package

roundcube

Package 20.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-35537

Medium priority
Needs evaluation

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.

1 affected package

roundcube

Package 20.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-35536

Medium priority
Fixed

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

1 affected package

python-tornado

Package 20.04 LTS
python-tornado Fixed
Show less packages

CVE-2026-35535

High priority
Not affected

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

1 affected package

sudo

Package 20.04 LTS
sudo Not affected
Show less packages

CVE-2026-27456

Medium priority
Vulnerable

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when...

1 affected package

util-linux

Package 20.04 LTS
util-linux Vulnerable
Show less packages

CVE-2026-35414

Medium priority
Needs evaluation

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

2 affected packages

openssh-ssh1, openssh

Package 20.04 LTS
openssh-ssh1 Ignored
openssh Needs evaluation
Show less packages

CVE-2026-34835

Medium priority
Not affected

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted...

1 affected package

ruby-rack

Package 20.04 LTS
ruby-rack Not affected
Show less packages

CVE-2026-34827

Medium priority
Ignored

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition:...

1 affected package

ruby-rack

Package 20.04 LTS
ruby-rack Ignored
Show less packages

CVE-2026-34601

Medium priority
Needs evaluation

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In xmldom versions 0.6.0 and prior and @xmldom/xmldom prior to versions 0.8.12 and 0.9.9, xmldom/xmldom...

1 affected package

node-xmldom

Package 20.04 LTS
node-xmldom Needs evaluation
Show less packages

CVE-2026-32762

Medium priority
Not affected

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling...

1 affected package

ruby-rack

Package 20.04 LTS
ruby-rack Not affected
Show less packages