Search CVE reports


Toggle filters

131 – 140 of 49076 results

Status is adjusted based on your filters.


CVE-2026-53626

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-53625

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, a technician can manipulate the authtype value through the API to change another user's authentication method. Under configurations using...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-53610

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, an attacker can craft a URL for a dashboard that reflects attacker-controlled markup without sufficient output encoding. A user who opens the...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-52727

Medium priority
Needs evaluation

(lxc-ci contains continuous integration and image-build scripts for LXC ...)

1 affected package

lxc-ci

Package 24.04 LTS
lxc-ci Needs evaluation
Show less packages

CVE-2026-51773

Medium priority
Needs evaluation

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the...

1 affected package

glance

Package 24.04 LTS
glance Needs evaluation
Show less packages

CVE-2026-51772

Medium priority
Needs evaluation

A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the...

1 affected package

glance

Package 24.04 LTS
glance Needs evaluation
Show less packages

CVE-2026-49470

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, the time-based one-time password verification endpoint does not limit failed submissions per user. An attacker who has obtained a user's primary...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-49469

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-48482

Medium priority

Not in release

GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset...

1 affected package

glpi

Package 24.04 LTS
glpi Not in release
Show less packages

CVE-2026-48188

Medium priority
Needs evaluation

(An improper Input Validation vulnerability in OTRS or ((OTRS)) Communi ...)

2 affected packages

znuny, otrs2

Package 24.04 LTS
znuny Needs evaluation
otrs2 Not in release
Show less packages