Search CVE reports


Toggle filters

1321 – 1330 of 56918 results

Status is adjusted based on your filters.


CVE-2026-23931

Medium priority
Needs evaluation

The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.

1 affected package

zabbix

Package 16.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2026-23930

Medium priority
Needs evaluation

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

1 affected package

zabbix

Package 16.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2026-23929

Medium priority
Needs evaluation

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation...

1 affected package

zabbix

Package 16.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2026-23922

Medium priority
Needs evaluation

The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.

1 affected package

zabbix

Package 16.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2026-1199

Medium priority
Needs evaluation

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

1 affected package

zabbix

Package 16.04 LTS
zabbix Needs evaluation
Show less packages

CVE-2026-18725

Medium priority
Needs evaluation

[Unknown description]

1 affected package

open-iscsi

Package 16.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-18724

Medium priority
Needs evaluation

[Unknown description]

1 affected package

open-iscsi

Package 16.04 LTS
open-iscsi Needs evaluation
Show less packages

CVE-2026-11817

Medium priority
Needs evaluation

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call...

1 affected package

grafana

Package 16.04 LTS
grafana Needs evaluation
Show less packages

CVE-2026-65640

Medium priority
Needs evaluation

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the...

1 affected package

wordpress

Package 16.04 LTS
wordpress Needs evaluation
Show less packages

CVE-2026-34789

Medium priority
Needs evaluation

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized...

1 affected package

freecad

Package 16.04 LTS
freecad Needs evaluation
Show less packages