Search CVE reports


Toggle filters

111 – 120 of 45011 results

Status is adjusted based on your filters.


CVE-2026-72746

Medium priority
Not affected

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Not affected
freerdp3
Show less packages

CVE-2026-72745

Medium priority
Not affected

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73242.

3 affected packages

freerdp, freerdp2, freerdp3

Package 20.04 LTS
freerdp
freerdp2 Not affected
freerdp3
Show less packages

CVE-2026-72712

Medium priority
Needs evaluation

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces...

1 affected package

nmap

Package 20.04 LTS
nmap Needs evaluation
Show less packages

CVE-2026-72694

Medium priority
Needs evaluation

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or...

1 affected package

mrtg

Package 20.04 LTS
mrtg Needs evaluation
Show less packages

CVE-2026-72693

Medium priority
Needs evaluation

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on...

1 affected package

kbd

Package 20.04 LTS
kbd Needs evaluation
Show less packages

CVE-2026-72556

Medium priority
Needs evaluation

A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent...

1 affected package

zoneminder

Package 20.04 LTS
zoneminder Needs evaluation
Show less packages

CVE-2026-71218

Medium priority
Needs evaluation

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the...

1 affected package

iperf3

Package 20.04 LTS
iperf3 Needs evaluation
Show less packages

CVE-2026-71217

Medium priority
Needs evaluation

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server....

1 affected package

iperf3

Package 20.04 LTS
iperf3 Needs evaluation
Show less packages

CVE-2026-71194

Medium priority
Needs evaluation

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with...

1 affected package

designate

Package 20.04 LTS
designate Needs evaluation
Show less packages

CVE-2026-71193

Medium priority
Needs evaluation

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone...

1 affected package

designate

Package 20.04 LTS
designate Needs evaluation
Show less packages