Search CVE reports


Toggle filters

151 – 160 of 33119 results

Status is adjusted based on your filters.


CVE-2026-19012

Medium priority

Not in release

Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul...

1 affected package

consul

Package 26.04 LTS
consul Not in release
Show less packages

CVE-2026-18649

Medium priority
Needs evaluation

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the reassembly buffer used during fragmented RTP packet processing. A...

1 affected package

gst-plugins-good1.0

Package 26.04 LTS
gst-plugins-good1.0 Needs evaluation
Show less packages

CVE-2026-18497

Medium priority
Needs evaluation

A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the...

1 affected package

libstb

Package 26.04 LTS
libstb Needs evaluation
Show less packages

CVE-2026-15972

Medium priority

Not in release

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent...

1 affected package

consul

Package 26.04 LTS
consul Not in release
Show less packages

CVE-2026-15970

Medium priority

Not in release

Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach...

1 affected package

consul

Package 26.04 LTS
consul Not in release
Show less packages

CVE-2026-15816

Medium priority
Needs evaluation

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the...

1 affected package

dracut

Package 26.04 LTS
dracut Needs evaluation
Show less packages

CVE-2026-13505

Medium priority
Needs evaluation

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material held by the AES and DESede engines, the SP 800-90A DRBGs, SymmetricSecretKey and...

1 affected package

bouncycastle

Package 26.04 LTS
bouncycastle Needs evaluation
Show less packages

CVE-2026-16742

Medium priority
Fixed

local privilege escalation via missing home-record signature verification on the authenticate path

1 affected package

systemd

Package 26.04 LTS
systemd Fixed
Show less packages

CVE-2026-15060

Medium priority
Fixed

unprivileged users can terminate arbitrary processes

1 affected package

systemd

Package 26.04 LTS
systemd Fixed
Show less packages

CVE-2026-15059

Medium priority
Fixed

unprivileged users can terminate arbitrary processes

1 affected package

systemd

Package 26.04 LTS
systemd Fixed
Show less packages