Search CVE reports


Toggle filters

51 – 60 of 41236 results

Status is adjusted based on your filters.


CVE-2026-9742

Medium priority
Needs evaluation

When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is accessible to unauthenticated...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-9741

Medium priority
Needs evaluation

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-9740

Medium priority
Needs evaluation

A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain nested binary data structures...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-9735

Medium priority
Needs evaluation

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-46433

Medium priority
Needs evaluation

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left....

2 affected packages

lldpd, openvswitch

Package 20.04 LTS
lldpd Needs evaluation
openvswitch Needs evaluation
Show less packages

CVE-2026-11824

Medium priority
Needs evaluation

SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with...

2 affected packages

sqlite, sqlite3

Package 20.04 LTS
sqlite Needs evaluation
sqlite3 Needs evaluation
Show less packages

CVE-2026-11822

Medium priority
Needs evaluation

SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database...

2 affected packages

sqlite, sqlite3

Package 20.04 LTS
sqlite Needs evaluation
sqlite3 Needs evaluation
Show less packages

CVE-2025-55659

Medium priority
Needs evaluation

A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-55658

Medium priority
Needs evaluation

GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages

CVE-2025-55657

Medium priority
Needs evaluation

A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

1 affected package

gpac

Package 20.04 LTS
gpac Needs evaluation
Show less packages