Search CVE reports


Toggle filters

21 – 30 of 43490 results

Status is adjusted based on your filters.


CVE-2026-50579

Medium priority
Needs evaluation

[Unknown description]

1 affected package

mbedtls

Package 20.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-49300

Medium priority
Needs evaluation

[Unknown description]

1 affected package

mbedtls

Package 20.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-35336

Medium priority
Needs evaluation

[Unknown description]

1 affected package

mbedtls

Package 20.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-25832

Medium priority
Needs evaluation

[Unknown description]

1 affected package

mbedtls

Package 20.04 LTS
mbedtls Needs evaluation
Show less packages

CVE-2026-9737

Medium priority
Needs evaluation

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-13078

Medium priority
Needs evaluation

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-13074

Medium priority
Needs evaluation

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-13072

Medium priority
Needs evaluation

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-13070

Medium priority
Needs evaluation

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages

CVE-2026-13069

Medium priority
Needs evaluation

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an...

1 affected package

mongodb

Package 20.04 LTS
mongodb Needs evaluation
Show less packages