Search CVE reports


Toggle filters

451 – 460 of 49237 results

Status is adjusted based on your filters.


CVE-2026-53610

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-49470

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-49469

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-48482

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-47679

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user can exploit insufficient path validation in the profile-picture update flow to request deletion of...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-45801

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user without the required permission can enable debug mode. The affected user-setting update does not enforce the...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-91841

Medium priority
Needs evaluation

A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to...

1 affected package

network-manager-vpnc

Package 24.04 LTS
network-manager-vpnc Needs evaluation
Show less packages

CVE-2026-91840

Medium priority
Needs evaluation

A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the...

1 affected package

network-manager-vpnc

Package 24.04 LTS
network-manager-vpnc Needs evaluation
Show less packages

CVE-2026-91839

Medium priority
Needs evaluation

A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local...

1 affected package

network-manager-fortisslvpn

Package 24.04 LTS
network-manager-fortisslvpn Needs evaluation
Show less packages

CVE-2026-91838

Medium priority
Needs evaluation

A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile...

1 affected package

network-manager-sstp

Package 24.04 LTS
network-manager-sstp Needs evaluation
Show less packages