Search CVE reports


Toggle filters

81 – 90 of 36041 results

Status is adjusted based on your filters.


CVE-2026-81727

Medium priority
Needs evaluation

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through...

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81726

Medium priority
Needs evaluation

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox...

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81725

Medium priority
Needs evaluation

NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI blocks with many unmatched opening tags....

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81724

Medium priority
Needs evaluation

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input....

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81723

Medium priority
Needs evaluation

NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can provide malformed XML corpus files...

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81722

Medium priority
Needs evaluation

nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire run of trailing 'y'...

1 affected package

nltk

Package 26.04 LTS
nltk Needs evaluation
Show less packages

CVE-2026-81525

Medium priority
Needs evaluation

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application...

1 affected package

php-mongodb

Package 26.04 LTS
php-mongodb Needs evaluation
Show less packages

CVE-2026-81524

Medium priority
Needs evaluation

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that...

1 affected package

mongo-c-driver

Package 26.04 LTS
mongo-c-driver Needs evaluation
Show less packages

CVE-2026-81523

Medium priority
Needs evaluation

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema...

1 affected package

libmongocrypt

Package 26.04 LTS
libmongocrypt Needs evaluation
Show less packages

CVE-2026-81522

Medium priority

Not in release

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace identifier from untrusted input without...

1 affected package

mongo-cxx-driver

Package 26.04 LTS
mongo-cxx-driver Not in release
Show less packages