Search CVE reports


Toggle filters

1161 – 1170 of 59834 results

Status is adjusted based on your filters.


CVE-2026-75973

Medium priority
Needs evaluation

Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9 —
tomcat10 —
tomcat11 —
Show less packages

CVE-2026-73581

Medium priority
Needs evaluation

Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue affects Apache Tomcat: from 11.0.0-M1 through...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 16.04 LTS
tomcat6 Not affected
tomcat7 Needs evaluation
tomcat8 Needs evaluation
tomcat9 —
tomcat10 —
tomcat11 —
Show less packages

CVE-2026-96442

Medium priority
Needs evaluation

A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking. Viewing or...

5 affected packages

emacs, xemacs21, xemacs21-packages, emacs24, emacs25

Package 16.04 LTS
emacs —
xemacs21 Needs evaluation
xemacs21-packages Needs evaluation
emacs24 Needs evaluation
emacs25 —
Show less packages

CVE-2026-91777

Medium priority
Needs evaluation

Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths...

1 affected package

jackson-databind

Package 16.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-91776

Medium priority
Needs evaluation

TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for...

1 affected package

jackson-databind

Package 16.04 LTS
jackson-databind Needs evaluation
Show less packages

CVE-2026-89425

Medium priority
Needs evaluation

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the...

1 affected package

jackson-core

Package 16.04 LTS
jackson-core Needs evaluation
Show less packages

CVE-2026-95516

Medium priority
Needs evaluation

[Unknown description]

1 affected package

zbar

Package 16.04 LTS
zbar Needs evaluation
Show less packages

CVE-2026-93403

Medium priority
Needs evaluation

[Stack-based Buffer Overflow in mmpstrucdata rsyslog plugin]

1 affected package

rsyslog

Package 16.04 LTS
rsyslog Needs evaluation
Show less packages

CVE-2026-93402

Medium priority
Needs evaluation

[mdtls discards the peer-identity verification result]

1 affected package

rsyslog

Package 16.04 LTS
rsyslog Needs evaluation
Show less packages

CVE-2026-92709

Medium priority
Needs evaluation

[Unknown description]

1 affected package

rsyslog

Package 16.04 LTS
rsyslog Needs evaluation
Show less packages