Search CVE reports


Toggle filters

1851 – 1860 of 37432 results

Status is adjusted based on your filters.


CVE-2026-19197

Medium priority

Not in release

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key...

1 affected package

grafana

Package 26.04 LTS
grafana Not in release
Show less packages

CVE-2026-18916

Medium priority
Needs evaluation

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.

1 affected package

nsd

Package 26.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-18664

Medium priority
Needs evaluation

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were...

1 affected package

nsd

Package 26.04 LTS
nsd Needs evaluation
Show less packages

CVE-2026-54467

Medium priority
Needs evaluation

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

1 affected package

arm-trusted-firmware

Package 26.04 LTS
arm-trusted-firmware Needs evaluation
Show less packages

CVE-2026-70665

Medium priority
Needs evaluation

Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without...

1 affected package

ruby-doorkeeper-openid-connect

Package 26.04 LTS
ruby-doorkeeper-openid-connect Needs evaluation
Show less packages

CVE-2026-44476

Medium priority
Needs evaluation

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and...

1 affected package

ruby-doorkeeper-openid-connect

Package 26.04 LTS
ruby-doorkeeper-openid-connect Needs evaluation
Show less packages

CVE-2026-80186

Medium priority
Needs evaluation

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer...

1 affected package

bluez

Package 26.04 LTS
bluez Needs evaluation
Show less packages

CVE-2026-80185

Medium priority
Needs evaluation

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence...

1 affected package

bluez

Package 26.04 LTS
bluez Needs evaluation
Show less packages

CVE-2026-80184

Medium priority
Needs evaluation

In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication...

1 affected package

keystone

Package 26.04 LTS
keystone Needs evaluation
Show less packages

CVE-2026-80182

Medium priority
Needs evaluation

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently...

1 affected package

keystone

Package 26.04 LTS
keystone Needs evaluation
Show less packages