Search CVE reports


Toggle filters

311 – 320 of 36824 results

Status is adjusted based on your filters.


CVE-2026-21932

Medium priority
Fixed

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471,...

12 affected packages

openjdk-9, openjdk-13, openjdk-16, openjdk-17-crac, openjdk-18...

Package 20.04 LTS
openjdk-9
openjdk-13 Ignored
openjdk-16 Ignored
openjdk-17-crac
openjdk-18
openjdk-21-crac
openjdk-8 Fixed
openjdk-21 Fixed
openjdk-17 Fixed
openjdk-lts Fixed
openjdk-25
openjdk-25-crac
Show all 12 packages Show less packages

CVE-2026-21929

Medium priority
Ignored

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Difficult to exploit vulnerability allows low privileged attacker with network access...

11 affected packages

mysql-5.5, mysql-5.7, mysql-8.0, mysql-8.4, mariadb...

Package 20.04 LTS
mysql-5.5
mysql-5.7
mysql-8.0 Not affected
mysql-8.4
mariadb
mariadb-10.0
mariadb-10.1
mariadb-10.3 Ignored
mariadb-10.6
percona-xtradb-cluster-5.6
percona-server-5.6
Show all 11 packages Show less packages

CVE-2026-21925

Medium priority
Fixed

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf,...

12 affected packages

openjdk-9, openjdk-13, openjdk-16, openjdk-17-crac, openjdk-18...

Package 20.04 LTS
openjdk-9
openjdk-13 Ignored
openjdk-16 Ignored
openjdk-17-crac
openjdk-18
openjdk-21-crac
openjdk-21 Fixed
openjdk-17 Fixed
openjdk-25
openjdk-8 Fixed
openjdk-lts Fixed
openjdk-25-crac
Show all 12 packages Show less packages

CVE-2026-0865

Medium priority

Some fixes available 2 of 3

User-controlled header names and values containing newlines can allow injecting HTTP headers.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 20.04 LTS
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Fixed
python3.9 Fixed
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2026-0672

Medium priority

Some fixes available 2 of 3

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 20.04 LTS
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Fixed
python3.9 Fixed
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15367

Medium priority

Some fixes available 2 of 3

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 20.04 LTS
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Fixed
python3.9 Fixed
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15366

Medium priority

Some fixes available 2 of 3

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 20.04 LTS
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Fixed
python3.9 Fixed
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15282

Medium priority

Some fixes available 2 of 3

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 20.04 LTS
python2.7 Needs evaluation
python3.4
python3.5
python3.6
python3.7
python3.8 Fixed
python3.9 Fixed
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-11468

Medium priority
Fixed

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled...

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 20.04 LTS
python2.7 Not affected
python3.4
python3.5
python3.6
python3.7
python3.8 Fixed
python3.9 Fixed
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2026-21637

Medium priority
Needs evaluation

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS...

1 affected package

nodejs

Package 20.04 LTS
nodejs Needs evaluation
Show less packages