Search CVE reports


Toggle filters

801 – 810 of 48899 results

Status is adjusted based on your filters.


CVE-2026-28375

Medium priority
Needs evaluation

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

1 affected package

grafana

Package 16.04 LTS
grafana Needs evaluation
Show less packages

CVE-2026-27880

Medium priority
Needs evaluation

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

1 affected package

grafana

Package 16.04 LTS
grafana Needs evaluation
Show less packages

CVE-2026-27879

Medium priority
Needs evaluation

A resample query can be used to trigger out-of-memory crashes in Grafana.

1 affected package

grafana

Package 16.04 LTS
grafana Needs evaluation
Show less packages

CVE-2026-27877

Medium priority
Needs evaluation

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to...

1 affected package

grafana

Package 16.04 LTS
grafana Needs evaluation
Show less packages

CVE-2026-27876

Medium priority
Needs evaluation

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid...

1 affected package

grafana

Package 16.04 LTS
grafana Needs evaluation
Show less packages

CVE-2026-4948

Medium priority
Needs evaluation

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to...

1 affected package

firewalld

Package 16.04 LTS
firewalld Needs evaluation
Show less packages

CVE-2026-34353

Medium priority
Needs evaluation

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.

1 affected package

ocaml

Package 16.04 LTS
ocaml Needs evaluation
Show less packages

CVE-2026-33721

Medium priority
Needs evaluation

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated...

1 affected package

mapserver

Package 16.04 LTS
mapserver Needs evaluation
Show less packages

CVE-2026-33699

Medium priority
Needs evaluation

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which leads to an infinite loop. This requires reading a file in non-strict mode. This has...

2 affected packages

pypdf, pypdf2

Package 16.04 LTS
pypdf
pypdf2 Needs evaluation
Show less packages

CVE-2026-33945

High priority
Not affected

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an...

2 affected packages

incus, lxd

Package 16.04 LTS
incus
lxd Not affected
Show less packages