Search CVE reports


Toggle filters

171 – 180 of 49410 results

Status is adjusted based on your filters.


CVE-2026-101887

Medium priority
Needs evaluation

BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero vulnerability in the LC3plus sink decoder (a2dp-lc3plus.c, a2dp_lc3plus_dec_thread) that allows a Bluetooth-adjacent attacker to crash the daemon by sending a crafted RTP...

1 affected package

bluez-alsa

Package 24.04 LTS
bluez-alsa Needs evaluation
Show less packages

CVE-2026-101283

Medium priority
Needs evaluation

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client...

1 affected package

iperf3

Package 24.04 LTS
iperf3 Needs evaluation
Show less packages

CVE-2026-101276

Medium priority
Needs evaluation

iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a...

1 affected package

iperf3

Package 24.04 LTS
iperf3 Needs evaluation
Show less packages

CVE-2026-102588

Medium priority

Not in release

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with grade management permissions into visiting a malicious webpage, an...

1 affected package

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2026-102587

Medium priority

Not in release

A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges can filter user lists using profile attributes they are not permitted...

1 affected package

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2026-102586

Medium priority

Not in release

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting (XSS) attack. By convincing an unauthenticated user to access...

1 affected package

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2026-102585

Medium priority

Not in release

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether the selected group actually belongs to that course. An authenticated user with teacher...

1 affected package

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2026-102584

Medium priority

Not in release

A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding the required permissions. This issue allows unauthorized users to...

1 affected package

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2026-102583

Medium priority

Not in release

A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user to invoke the feature without holding the...

1 affected package

moodle

Package 24.04 LTS
moodle Not in release
Show less packages

CVE-2026-102582

Medium priority

Not in release

A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with enrolment permissions to access the page directly by navigating to its...

1 affected package

moodle

Package 24.04 LTS
moodle Not in release
Show less packages