Search CVE reports


Toggle filters

451 – 460 of 37500 results

Status is adjusted based on your filters.


CVE-2026-89087

Medium priority
Needs evaluation

The cstruct package before 6.3.0 for OCaml mishandles indexes.

1 affected package

ocaml-cstruct

Package 26.04 LTS
ocaml-cstruct Needs evaluation
Show less packages

CVE-2026-88914

Medium priority
Needs evaluation

A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds...

1 affected package

gst-plugins-good1.0

Package 26.04 LTS
gst-plugins-good1.0 Needs evaluation
Show less packages

CVE-2026-88038

Medium priority
Needs evaluation

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator,...

1 affected package

node-cookies

Package 26.04 LTS
node-cookies Needs evaluation
Show less packages

CVE-2026-88036

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-88034

Medium priority

Not in release

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

mongo-cxx-driver

Package 26.04 LTS
mongo-cxx-driver Not in release
Show less packages

CVE-2026-88033

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

mongo-java-driver

Package 26.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-88032

Medium priority
Needs evaluation

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party...

1 affected package

mongo-java-driver

Package 26.04 LTS
mongo-java-driver Needs evaluation
Show less packages

CVE-2026-88031

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

golang-mongodb-mongo-driver

Package 26.04 LTS
golang-mongodb-mongo-driver Needs evaluation
Show less packages

CVE-2026-88030

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

ruby-mongo

Package 26.04 LTS
ruby-mongo Needs evaluation
Show less packages

CVE-2026-88029

Medium priority
Needs evaluation

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a...

1 affected package

pymongo

Package 26.04 LTS
pymongo Needs evaluation
Show less packages