Search CVE reports


Toggle filters

691 – 700 of 36830 results

Status is adjusted based on your filters.


CVE-2026-1933

Medium priority
Not affected

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or...

1 affected package

samba

Package 24.04 LTS
samba Not affected
Show less packages

CVE-2026-48852

Medium priority
Needs evaluation

PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

1 affected package

putty

Package 24.04 LTS
putty Needs evaluation
Show less packages

CVE-2026-48851

Medium priority
Needs evaluation

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.

1 affected package

putty

Package 24.04 LTS
putty Needs evaluation
Show less packages

CVE-2026-48850

Medium priority
Needs evaluation

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

1 affected package

putty

Package 24.04 LTS
putty Needs evaluation
Show less packages

CVE-2026-48589

Medium priority
Needs evaluation

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value could allow an attacker to...

1 affected package

shiro

Package 24.04 LTS
shiro Needs evaluation
Show less packages

CVE-2026-44598

Medium priority
Needs evaluation

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha to 2.1.0, and 3.0.0-alpha-1, only...

1 affected package

shiro

Package 24.04 LTS
shiro Needs evaluation
Show less packages

CVE-2026-43828

Medium priority
Needs evaluation

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or...

1 affected package

shiro

Package 24.04 LTS
shiro Needs evaluation
Show less packages

CVE-2026-43827

Medium priority
Needs evaluation

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later,...

1 affected package

shiro

Package 24.04 LTS
shiro Needs evaluation
Show less packages

CVE-2026-48849

Medium priority
Needs evaluation

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages

CVE-2026-48848

Medium priority
Needs evaluation

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute.

1 affected package

roundcube

Package 24.04 LTS
roundcube Needs evaluation
Show less packages