Search CVE reports


Toggle filters

941 – 950 of 33861 results

Status is adjusted based on your filters.


CVE-2026-23924

Medium priority

Not in release

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23921

Medium priority

Not in release

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23920

Medium priority

Not in release

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-23919

Medium priority

Not in release

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator...

1 affected package

zabbix

Package 24.04 LTS
zabbix Not in release
Show less packages

CVE-2026-32854

Medium priority
Needs evaluation

LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the HTTP proxy handlers within httpProcessInput() in httpd.c that allow remote attackers to cause a denial of...

6 affected packages

libvncserver, vino, x11vnc, veyon, italc, tightvnc

Package 24.04 LTS
libvncserver Needs evaluation
vino Needs evaluation
x11vnc Needs evaluation
veyon Needs evaluation
italc Not in release
tightvnc Needs evaluation
Show less packages

CVE-2026-32853

Medium priority
Needs evaluation

LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the UltraZip encoding handler that allows a malicious VNC server to cause information disclosure or application...

6 affected packages

veyon, libvncserver, vino, x11vnc, italc, tightvnc

Package 24.04 LTS
veyon Needs evaluation
libvncserver Needs evaluation
vino Needs evaluation
x11vnc Needs evaluation
italc Not in release
tightvnc Needs evaluation
Show less packages

CVE-2026-4775

Medium priority
Needs evaluation

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile function by providing a specially crafted TIFF file. This flaw can lead to an...

5 affected packages

tiff, qtwebengine-opensource-src, texmaker, gdal, neuron

Package 24.04 LTS
tiff Needs evaluation
qtwebengine-opensource-src Needs evaluation
texmaker Needs evaluation
gdal Not affected
neuron Not affected
Show less packages

CVE-2026-33554

Low priority
Needs evaluation

ipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented...

1 affected package

freeipmi

Package 24.04 LTS
freeipmi Needs evaluation
Show less packages

CVE-2026-27784

Medium priority
Needs evaluation

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially...

1 affected package

nginx

Package 24.04 LTS
nginx Needs evaluation
Show less packages

CVE-2026-27654

Medium priority
Needs evaluation

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the...

1 affected package

nginx

Package 24.04 LTS
nginx Needs evaluation
Show less packages