Search CVE reports


Toggle filters

1 – 10 of 63792 results


CVE-2026-25934

Medium priority
Needs evaluation

go-git is a highly extensible git implementation library written in pure Go. Prior to 5.16.5, a vulnerability was discovered in go-git whereby data integrity values for .pack and .idx files were not properly verified....

1 affected package

golang-github-go-git-go-git

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-git-go-git Needs evaluation Needs evaluation
Show less packages

CVE-2026-25918

Medium priority
Needs evaluation

unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line...

1 affected package

unity

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unity Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25916

Medium priority
Needs evaluation

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

1 affected package

roundcube

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
roundcube Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25892

Medium priority
Needs evaluation

Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version....

1 affected package

adminer

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
adminer Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25765

Medium priority
Needs evaluation

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the...

1 affected package

ruby-faraday

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-faraday Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24095

Medium priority
Needs evaluation

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its...

1 affected package

check-mk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
check-mk Not in release Not in release Needs evaluation
Show less packages

CVE-2026-24027

Medium priority
Needs evaluation

Crafted zones can lead to increased incoming network traffic.

1 affected package

pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-23948

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially...

3 affected packages

freerdp, freerdp2, freerdp3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
freerdp Not in release Not in release Needs evaluation
freerdp2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
freerdp3 Needs evaluation Not in release
Show less packages

CVE-2026-23903

Medium priority
Needs evaluation

Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files....

1 affected package

shiro

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shiro Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-23901

Medium priority
Needs evaluation

[shiro: Brute force attack possible to determine valid user names]

1 affected package

shiro

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
shiro Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages