Search CVE reports


Toggle filters

371 – 380 of 35883 results

Status is adjusted based on your filters.


CVE-2026-21936

Medium priority

Some fixes available 1 of 2

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker...

11 affected packages

mysql-5.5, mysql-5.7, mysql-8.0, mysql-8.4, mariadb...

Package 22.04 LTS
mysql-5.5 Not in release
mysql-5.7 Not in release
mysql-8.0 Fixed
mysql-8.4 Not in release
mariadb Not in release
mariadb-10.0 Not in release
mariadb-10.1 Not in release
mariadb-10.3 Not in release
mariadb-10.6 Needs evaluation
percona-xtradb-cluster-5.6 Not in release
percona-server-5.6 Not in release
Show all 11 packages Show less packages

CVE-2026-21933

Medium priority
Fixed

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471,...

12 affected packages

openjdk-9, openjdk-13, openjdk-16, openjdk-17-crac, openjdk-18...

Package 22.04 LTS
openjdk-9 Not in release
openjdk-13 Not in release
openjdk-16 Not in release
openjdk-17-crac Not in release
openjdk-18 Ignored
openjdk-8 Fixed
openjdk-21 Fixed
openjdk-17 Fixed
openjdk-21-crac Not in release
openjdk-25 Fixed
openjdk-lts Fixed
openjdk-25-crac Not in release
Show all 12 packages Show less packages

CVE-2026-21932

Medium priority
Fixed

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471,...

12 affected packages

openjdk-9, openjdk-13, openjdk-16, openjdk-17-crac, openjdk-18...

Package 22.04 LTS
openjdk-9 Not in release
openjdk-13 Not in release
openjdk-16 Not in release
openjdk-17-crac Not in release
openjdk-18 Ignored
openjdk-21-crac Not in release
openjdk-8 Fixed
openjdk-21 Fixed
openjdk-17 Fixed
openjdk-lts Fixed
openjdk-25 Fixed
openjdk-25-crac Not in release
Show all 12 packages Show less packages

CVE-2026-21929

Medium priority
Needs evaluation

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Difficult to exploit vulnerability allows low privileged attacker with network access...

11 affected packages

mysql-5.5, mysql-5.7, mysql-8.0, mysql-8.4, mariadb...

Package 22.04 LTS
mysql-5.5 Not in release
mysql-5.7 Not in release
mysql-8.0 Not affected
mysql-8.4 Not in release
mariadb Not in release
mariadb-10.0 Not in release
mariadb-10.1 Not in release
mariadb-10.3 Not in release
mariadb-10.6 Needs evaluation
percona-xtradb-cluster-5.6 Not in release
percona-server-5.6 Not in release
Show all 11 packages Show less packages

CVE-2026-21925

Medium priority
Fixed

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf,...

12 affected packages

openjdk-9, openjdk-13, openjdk-16, openjdk-17-crac, openjdk-18...

Package 22.04 LTS
openjdk-9 Not in release
openjdk-13 Not in release
openjdk-16 Not in release
openjdk-17-crac Not in release
openjdk-18 Ignored
openjdk-21-crac Not in release
openjdk-21 Fixed
openjdk-17 Fixed
openjdk-25 Fixed
openjdk-8 Fixed
openjdk-lts Fixed
openjdk-25-crac Not in release
Show all 12 packages Show less packages

CVE-2026-0865

Medium priority

Some fixes available 2 of 3

User-controlled header names and values containing newlines can allow injecting HTTP headers.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 22.04 LTS
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Fixed
python3.11 Fixed
python3.12 Not in release
python3.13 Not in release
python3.14 Not in release
Show all 12 packages Show less packages

CVE-2026-0672

Medium priority

Some fixes available 2 of 3

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 22.04 LTS
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Fixed
python3.11 Fixed
python3.12 Not in release
python3.13 Not in release
python3.14 Not in release
Show all 12 packages Show less packages

CVE-2025-15367

Medium priority

Some fixes available 2 of 3

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 22.04 LTS
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Fixed
python3.11 Fixed
python3.12 Not in release
python3.13 Not in release
python3.14 Not in release
Show all 12 packages Show less packages

CVE-2025-15366

Medium priority

Some fixes available 2 of 3

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 22.04 LTS
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Fixed
python3.11 Fixed
python3.12 Not in release
python3.13 Not in release
python3.14 Not in release
Show all 12 packages Show less packages

CVE-2025-15282

Medium priority

Some fixes available 2 of 3

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 22.04 LTS
python2.7 Needs evaluation
python3.4 Not in release
python3.5 Not in release
python3.6 Not in release
python3.7 Not in release
python3.8 Not in release
python3.9 Not in release
python3.10 Fixed
python3.11 Fixed
python3.12 Not in release
python3.13 Not in release
python3.14 Not in release
Show all 12 packages Show less packages