Search CVE reports


Toggle filters

1 – 10 of 41454 results

Status is adjusted based on your filters.


CVE-2026-25918

Medium priority
Needs evaluation

unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line...

1 affected package

unity

Package 18.04 LTS
unity Needs evaluation
Show less packages

CVE-2026-25916

Medium priority
Needs evaluation

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

1 affected package

roundcube

Package 18.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-25892

Medium priority
Needs evaluation

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version....

1 affected package

adminer

Package 18.04 LTS
adminer Needs evaluation
Show less packages

CVE-2026-25765

Medium priority
Needs evaluation

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the...

1 affected package

ruby-faraday

Package 18.04 LTS
ruby-faraday Needs evaluation
Show less packages

CVE-2026-24095

Medium priority
Needs evaluation

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its...

1 affected package

check-mk

Package 18.04 LTS
check-mk Needs evaluation
Show less packages

CVE-2026-24027

Medium priority
Needs evaluation

Crafted zones can lead to increased incoming network traffic.

1 affected package

pdns-recursor

Package 18.04 LTS
pdns-recursor Needs evaluation
Show less packages

CVE-2026-23948

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially...

3 affected packages

freerdp, freerdp2, freerdp3

Package 18.04 LTS
freerdp Needs evaluation
freerdp2 Needs evaluation
freerdp3
Show less packages

CVE-2026-23903

Medium priority
Needs evaluation

Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files....

1 affected package

shiro

Package 18.04 LTS
shiro Needs evaluation
Show less packages

CVE-2026-23901

Medium priority
Needs evaluation

[shiro: Brute force attack possible to determine valid user names]

1 affected package

shiro

Package 18.04 LTS
shiro Needs evaluation
Show less packages

CVE-2026-1584

High priority
Not affected

A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server.

1 affected package

gnutls28

Package 18.04 LTS
gnutls28 Not affected
Show less packages