Search CVE reports


Toggle filters

71 – 80 of 42336 results

Status is adjusted based on your filters.


CVE-2026-48554

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48553

Medium priority
Needs evaluation

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48552

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization,...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48551

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-48550

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by...

1 affected package

nagios4

Package 24.04 LTS
nagios4 Needs evaluation
Show less packages

CVE-2026-29036

Medium priority
Needs evaluation

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations...

1 affected package

cjson

Package 24.04 LTS
cjson Needs evaluation
Show less packages

CVE-2026-29035

Medium priority
Needs evaluation

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both...

1 affected package

civetweb

Package 24.04 LTS
civetweb Needs evaluation
Show less packages

CVE-2026-20917

Medium priority
Needs evaluation

Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a...

1 affected package

intel-microcode

Package 24.04 LTS
intel-microcode Needs evaluation
Show less packages

CVE-2026-20901

Medium priority
Needs evaluation

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data...

1 affected package

intel-microcode

Package 24.04 LTS
intel-microcode Needs evaluation
Show less packages

CVE-2026-20760

Medium priority
Needs evaluation

Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with...

1 affected package

intel-microcode

Package 24.04 LTS
intel-microcode Needs evaluation
Show less packages