Search CVE reports


Toggle filters

681 – 690 of 52944 results

Status is adjusted based on your filters.


CVE-2026-79310

Medium priority
Needs evaluation

webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When...

1 affected package

webpy

Package 22.04 LTS
webpy Needs evaluation
Show less packages

CVE-2026-78437

Medium priority
Needs evaluation

Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through 11.0.25,...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 22.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Not in release
tomcat11 Not in release
Show less packages

CVE-2026-78383

Medium priority
Needs evaluation

Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service. This issue affects Apache Tomcat: from...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 22.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Not in release
tomcat11 Not in release
Show less packages

CVE-2026-78253

Medium priority
Needs evaluation

Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML document.

2 affected packages

qt6-base, qtbase-opensource-src

Package 22.04 LTS
qt6-base Needs evaluation
qtbase-opensource-src Needs evaluation
Show less packages

CVE-2026-77791

Medium priority
Needs evaluation

Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 22.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Not in release
tomcat11 Not in release
Show less packages

CVE-2026-77762

Medium priority
Needs evaluation

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. This issue affects Apache Tomcat:...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 22.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Not in release
tomcat11 Not in release
Show less packages

CVE-2026-77756

Medium priority
Needs evaluation

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an attacker to cause one request...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 22.04 LTS
tomcat6 Not in release
tomcat7 Not in release
tomcat8 Not in release
tomcat9 Needs evaluation
tomcat10 Not in release
tomcat11 Not in release
Show less packages

CVE-2026-77423

Medium priority
Needs evaluation

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in...

3 affected packages

jline, jline2, jline3

Package 22.04 LTS
jline Needs evaluation
jline2 Needs evaluation
jline3 Needs evaluation
Show less packages

CVE-2026-77422

Medium priority
Needs evaluation

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression...

3 affected packages

jline, jline2, jline3

Package 22.04 LTS
jline Needs evaluation
jline2 Needs evaluation
jline3 Needs evaluation
Show less packages

CVE-2026-77421

Medium priority
Needs evaluation

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text)...

3 affected packages

jline, jline2, jline3

Package 22.04 LTS
jline Needs evaluation
jline2 Needs evaluation
jline3 Needs evaluation
Show less packages