Search CVE reports


Toggle filters

111 – 120 of 42933 results

Status is adjusted based on your filters.


CVE-2026-33455

Medium priority
Needs evaluation

Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livestatus commands via the search query due to insufficient input sanitization in search filter plugins.

1 affected package

check-mk

Package 18.04 LTS
check-mk Needs evaluation
Show less packages

CVE-2026-32990

Medium priority
Needs evaluation

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 18.04 LTS
tomcat6
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9 Needs evaluation
tomcat10
tomcat11
Show less packages

CVE-2026-30479

Medium priority
Needs evaluation

A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted executable.

1 affected package

mapserver

Package 18.04 LTS
mapserver Needs evaluation
Show less packages

CVE-2026-29146

Medium priority
Needs evaluation

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 18.04 LTS
tomcat6
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9 Needs evaluation
tomcat10
tomcat11
Show less packages

CVE-2026-29145

Medium priority
Needs evaluation

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18,...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 18.04 LTS
tomcat6
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9 Needs evaluation
tomcat10
tomcat11
Show less packages

CVE-2026-29129

Medium priority
Needs evaluation

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 18.04 LTS
tomcat6
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9 Needs evaluation
tomcat10
tomcat11
Show less packages

CVE-2026-25854

Medium priority
Needs evaluation

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52,...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 18.04 LTS
tomcat6
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9 Needs evaluation
tomcat10
tomcat11
Show less packages

CVE-2026-24880

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 18.04 LTS
tomcat6
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9 Needs evaluation
tomcat10
tomcat11
Show less packages

CVE-2025-15480

Medium priority
Not affected

In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, ubuntu-desktop-provision could include the...

1 affected package

subiquity

Package 18.04 LTS
subiquity Not affected
Show less packages

CVE-2025-14551

Medium priority
Needs evaluation

In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiquity could include certain user credentials, such as...

1 affected package

subiquity

Package 18.04 LTS
subiquity Needs evaluation
Show less packages