Search CVE reports


Toggle filters

71 – 80 of 53354 results

Status is adjusted based on your filters.


CVE-2026-73281

Medium priority
Needs evaluation

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and...

2 affected packages

openssh, openssh-ssh1

Package 16.04 LTS
openssh Needs evaluation
openssh-ssh1
Show less packages

CVE-2026-73249

Medium priority
Needs evaluation

calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip...

1 affected package

calibre

Package 16.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-73248

Medium priority
Needs evaluation

calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does...

1 affected package

calibre

Package 16.04 LTS
calibre Needs evaluation
Show less packages

CVE-2026-73242

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before...

3 affected packages

freerdp, freerdp2, freerdp3

Package 16.04 LTS
freerdp Needs evaluation
freerdp2
freerdp3
Show less packages

CVE-2026-73241

Medium priority
Needs evaluation

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is...

3 affected packages

freerdp, freerdp2, freerdp3

Package 16.04 LTS
freerdp Needs evaluation
freerdp2
freerdp3
Show less packages

CVE-2026-73229

Medium priority
Needs evaluation

Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and...

1 affected package

djangorestframework

Package 16.04 LTS
djangorestframework Needs evaluation
Show less packages

CVE-2026-73228

Medium priority
Needs evaluation

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser...

1 affected package

djangorestframework

Package 16.04 LTS
djangorestframework Needs evaluation
Show less packages

CVE-2026-73216

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth accounting during...

1 affected package

coturn

Package 16.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-73215

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for an EVEN-PORT Allocate request...

1 affected package

coturn

Package 16.04 LTS
coturn Needs evaluation
Show less packages

CVE-2026-73214

Medium priority
Needs evaluation

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment()...

1 affected package

coturn

Package 16.04 LTS
coturn Needs evaluation
Show less packages