Search CVE reports


Toggle filters

2881 – 2890 of 49652 results

Status is adjusted based on your filters.


CVE-2026-21936

Medium priority
Needs evaluation

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker...

11 affected packages

mysql-5.5, mysql-5.7, mysql-8.0, mysql-8.4, mariadb...

Package 16.04 LTS
mysql-5.5
mysql-5.7 Ignored
mysql-8.0
mysql-8.4
mariadb
mariadb-10.0 Not affected
mariadb-10.1
mariadb-10.3
mariadb-10.6
percona-xtradb-cluster-5.6 Needs evaluation
percona-server-5.6 Needs evaluation
Show all 11 packages Show less packages

CVE-2026-21933

Medium priority

Some fixes available 1 of 2

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u471,...

12 affected packages

openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...

Package 16.04 LTS
openjdk-8 Fixed
openjdk-9 Ignored
openjdk-lts
openjdk-13
openjdk-16
openjdk-17
openjdk-17-crac
openjdk-18
openjdk-21
openjdk-21-crac
openjdk-25
openjdk-25-crac
Show all 12 packages Show less packages

CVE-2026-21932

Medium priority

Some fixes available 1 of 2

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX). Supported versions that are affected are Oracle Java SE: 8u471,...

12 affected packages

openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...

Package 16.04 LTS
openjdk-8 Fixed
openjdk-9 Ignored
openjdk-lts
openjdk-13
openjdk-16
openjdk-17
openjdk-17-crac
openjdk-18
openjdk-21
openjdk-21-crac
openjdk-25
openjdk-25-crac
Show all 12 packages Show less packages

CVE-2026-21929

Medium priority
Needs evaluation

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 9.0.0-9.5.0. Difficult to exploit vulnerability allows low privileged attacker with network access...

11 affected packages

mysql-5.5, mysql-5.7, mysql-8.0, mysql-8.4, mariadb...

Package 16.04 LTS
mysql-5.5
mysql-5.7 Ignored
mysql-8.0
mysql-8.4
mariadb
mariadb-10.0 Not affected
mariadb-10.1
mariadb-10.3
mariadb-10.6
percona-xtradb-cluster-5.6 Needs evaluation
percona-server-5.6 Needs evaluation
Show all 11 packages Show less packages

CVE-2026-21925

Medium priority

Some fixes available 1 of 2

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf,...

12 affected packages

openjdk-8, openjdk-9, openjdk-lts, openjdk-13, openjdk-16...

Package 16.04 LTS
openjdk-8 Fixed
openjdk-9 Ignored
openjdk-lts
openjdk-13
openjdk-16
openjdk-17
openjdk-17-crac
openjdk-18
openjdk-21
openjdk-21-crac
openjdk-25
openjdk-25-crac
Show all 12 packages Show less packages

CVE-2026-0865

Medium priority
Fixed

User-controlled header names and values containing newlines can allow injecting HTTP headers.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Fixed
python3.4
python3.5 Fixed
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2026-0672

Medium priority
Fixed

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Fixed
python3.4
python3.5 Fixed
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15367

Medium priority
Ignored

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Ignored
python3.4
python3.5 Ignored
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15366

Medium priority
Ignored

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Ignored
python3.4
python3.5 Ignored
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages

CVE-2025-15282

Medium priority
Fixed

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

12 affected packages

python2.7, python3.4, python3.5, python3.6, python3.7...

Package 16.04 LTS
python2.7 Fixed
python3.4
python3.5 Fixed
python3.6
python3.7
python3.8
python3.9
python3.10
python3.11
python3.12
python3.13
python3.14
Show all 12 packages Show less packages