Search CVE reports


Toggle filters

711 – 720 of 57535 results

Status is adjusted based on your filters.


CVE-2026-82052

Medium priority
Needs evaluation

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of...

1 affected package

mongodb

Package 16.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-19203

Medium priority
Needs evaluation

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, potentially resulting in HTTP request smuggling. This is caused...

3 affected packages

jetty, jetty12, jetty9

Package 16.04 LTS
jetty Needs evaluation
jetty12
jetty9 Needs evaluation
Show less packages

CVE-2026-12611

Medium priority
Needs evaluation

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race...

2 affected packages

jetty12, jetty9

Package 16.04 LTS
jetty12
jetty9 Needs evaluation
Show less packages

CVE-2026-74860

Medium priority
Needs evaluation

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute...

1 affected package

libxml2

Package 16.04 LTS
libxml2 Needs evaluation
Show less packages

CVE-2026-79604

Medium priority
Needs evaluation

oxenstored: Unbounded accumulation of watches: Oxenstored maintains two datastructures about watches; one global trie, and one hashtable tracked per domain. When a xenbus reconnect is requested, watches are not cleared out of the...

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-79603

Medium priority
Needs evaluation

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB...

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-79602

Medium priority
Needs evaluation

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-62437

Medium priority
Needs evaluation

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated removal of tracking structures for IRQs used by the devices occurs...

1 affected package

xen

Package 16.04 LTS
xen Needs evaluation
Show less packages

CVE-2026-19614

Medium priority
Needs evaluation

The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.

1 affected package

libnanoxml2-java

Package 16.04 LTS
libnanoxml2-java Needs evaluation
Show less packages

CVE-2026-76561

Medium priority
Needs evaluation

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with...

1 affected package

dogtag-pki

Package 16.04 LTS
dogtag-pki Needs evaluation
Show less packages