Search CVE reports


Toggle filters

71 – 80 of 36094 results

Status is adjusted based on your filters.


CVE-2025-54514

Medium priority
Needs evaluation

Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could potentially lead to a partial loss of integrity.

1 affected package

amd64-microcode

Package 22.04 LTS
amd64-microcode Needs evaluation
Show less packages

CVE-2025-52536

Medium priority
Needs evaluation

Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting in a loss of integrity.

1 affected package

amd64-microcode

Package 22.04 LTS
amd64-microcode Needs evaluation
Show less packages

CVE-2025-52534

Medium priority
Needs evaluation

Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.

1 affected package

amd64-microcode

Package 22.04 LTS
amd64-microcode Needs evaluation
Show less packages

CVE-2025-48517

Medium priority
Needs evaluation

Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial...

1 affected package

amd64-microcode

Package 22.04 LTS
amd64-microcode Needs evaluation
Show less packages

CVE-2025-48514

Medium priority
Needs evaluation

Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.

1 affected package

amd64-microcode

Package 22.04 LTS
amd64-microcode Needs evaluation
Show less packages

CVE-2026-25613

Medium priority

Not in release

An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-25610

Medium priority

Not in release

An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-25609

Medium priority

Not in release

Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read-only.

1 affected package

mongodb

Package 22.04 LTS
mongodb Not in release
Show less packages

CVE-2026-25506

Medium priority
Fixed

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key...

1 affected package

munge

Package 22.04 LTS
munge Fixed
Show less packages

CVE-2026-2302

Medium priority
Needs evaluation

Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.

1 affected package

ruby-mongo

Package 22.04 LTS
ruby-mongo Needs evaluation
Show less packages