Search CVE reports


Toggle filters

21 – 30 of 59781 results

Status is adjusted based on your filters.


CVE-2026-63045

Medium priority
Needs evaluation

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-61813

Medium priority
Needs evaluation

[GHSA-2vqc-36qp-ccmw: Weak libcurl TLS hostname verification setting when fetching over HTTPS]

2 affected packages

modsecurity, modsecurity-apache

Package 16.04 LTS
modsecurity —
modsecurity-apache Needs evaluation
Show less packages

CVE-2026-61812

Medium priority
Needs evaluation

[GHSA-cxqf-vgrr-xxrv: HTML decoder missing entities, leading to evasion]

2 affected packages

modsecurity, modsecurity-apache

Package 16.04 LTS
modsecurity —
modsecurity-apache Needs evaluation
Show less packages

CVE-2026-59797

Medium priority
Needs evaluation

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-59685

Medium priority
Needs evaluation

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-58415

Medium priority
Needs evaluation

Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author...

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-57941

Medium priority
Needs evaluation

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-56449

Medium priority
Needs evaluation

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-56154

Medium priority
Needs evaluation

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages

CVE-2026-56153

Medium priority
Needs evaluation

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

1 affected package

apache2

Package 16.04 LTS
apache2 Needs evaluation
Show less packages