Search CVE reports


Toggle filters

11 – 20 of 33696 results

Status is adjusted based on your filters.


CVE-2026-18691

Medium priority

Not in release

(An issue in MongoDB Server's intra-cluster connection setup could allo ...)

1 affected package

mongodb

Package 26.04 LTS
mongodb Not in release
Show less packages

CVE-2026-18690

Medium priority

Not in release

(An issue in MongoDB Server could allow an authenticated user with a li ...)

1 affected package

mongodb

Package 26.04 LTS
mongodb Not in release
Show less packages

CVE-2026-18688

Medium priority

Not in release

(An issue in MongoDB Server's aggregation framework could allow an auth ...)

1 affected package

mongodb

Package 26.04 LTS
mongodb Not in release
Show less packages

CVE-2026-18687

Medium priority

Not in release

(MongoDB Server's handling of a Queryable Encryption maintenance operat ...)

1 affected package

mongodb

Package 26.04 LTS
mongodb Not in release
Show less packages

CVE-2026-13002

Medium priority
Needs evaluation

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution...

1 affected package

dnsmasq

Package 26.04 LTS
dnsmasq Needs evaluation
Show less packages

CVE-2025-71405

Medium priority
Needs evaluation

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to...

1 affected package

golang-github-go-chi-chi

Package 26.04 LTS
golang-github-go-chi-chi Needs evaluation
Show less packages

CVE-2026-73648

Medium priority
Needs evaluation

(rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)

1 affected package

ruby-rails-html-sanitizer

Package 26.04 LTS
ruby-rails-html-sanitizer Needs evaluation
Show less packages

CVE-2026-73643

Medium priority
Needs evaluation

(js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2 ...)

1 affected package

node-js-yaml

Package 26.04 LTS
node-js-yaml Needs evaluation
Show less packages

CVE-2026-73627

Medium priority
Needs evaluation

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator...

1 affected package

jupyterlab

Package 26.04 LTS
jupyterlab Needs evaluation
Show less packages

CVE-2026-73626

Medium priority
Needs evaluation

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension...

1 affected package

jupyterlab

Package 26.04 LTS
jupyterlab Needs evaluation
Show less packages