Search CVE reports


Toggle filters

31 – 40 of 42490 results

Status is adjusted based on your filters.


CVE-2026-33898

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui`...

2 affected packages

incus, lxd

Package 18.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-33897

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances...

2 affected packages

incus, lxd

Package 18.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-33871

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of...

1 affected package

netty

Package 18.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-33870

Medium priority
Needs evaluation

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling...

1 affected package

netty

Package 18.04 LTS
netty Needs evaluation
Show less packages

CVE-2026-33750

Medium priority
Needs evaluation

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a brace pattern with a zero step value (e.g., `{1..2..0}`) causes the sequence...

1 affected package

node-brace-expansion

Package 18.04 LTS
node-brace-expansion Needs evaluation
Show less packages

CVE-2026-33743

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated...

2 affected packages

incus, lxd

Package 18.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-33721

Medium priority
Needs evaluation

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated...

1 affected package

mapserver

Package 18.04 LTS
mapserver Needs evaluation
Show less packages

CVE-2026-33711

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the...

2 affected packages

incus, lxd

Package 18.04 LTS
incus
lxd Needs evaluation
Show less packages

CVE-2026-33672

Medium priority
Needs evaluation

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method injection vulnerability affecting the `POSIX_REGEX_SOURCE` object. Because the object inherits...

1 affected package

node-anymatch

Package 18.04 LTS
node-anymatch Needs evaluation
Show less packages

CVE-2026-33671

Medium priority
Needs evaluation

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob...

1 affected package

node-anymatch

Package 18.04 LTS
node-anymatch Needs evaluation
Show less packages