Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Cassandra MEDIUM 6.5
CVE-2026-32588

Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users …

Fix: 4.0.20 / 4.1.11+
Fix from $1,600 2026-04-07
Directus MEDIUM 6.5
CVE-2026-35441

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql…

Fix: 11.17.0+
Fix from $1,600 2026-04-06
Exynos 990 Firmware HIGH 7.5
CVE-2025-54324

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1…

Mitigation only
Fix from $1,950 2026-04-06
Exynos 990 Firmware CRITICAL 9.1
CVE-2025-58349

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14…

Mitigation only
Fix from $2,300 2026-04-06
Android MEDIUM 6.2
CVE-2026-0049

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local …

Mitigation only
Fix from $1,600 2026-04-06
Exynos 990 Firmware HIGH 7.5
CVE-2025-59440

An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, …

Mitigation only
Fix from $1,950 2026-04-06
Fedify\/fedify HIGH 7.5
CVE-2026-34148

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify fo…

Fix: 1.9.6 / 1.10.5+
Fix from $1,950 2026-04-06
Eaglesdv Firmware HIGH 7.5
CVE-2022-4986

Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establ…

Fix: 05.4.02+
Fix from $1,950 2026-04-02
Unclassified HIGH 7.5
CVE-2024-14033

Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. Attackers can crash the device…

Mitigation only
Fix from $1,950 2026-04-02
Rack HIGH 7.5
CVE-2026-34827

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mi…

Fix: 3.1.21 / 3.2.6+
Fix from $1,950 2026-04-02
Ash Framework HIGH 7.5
CVE-2026-34593

Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 uncondit…

Fix: 3.22.0+
Fix from $1,950 2026-04-02
Rack HIGH 7.5
CVE-2026-34829

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a Bo…

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Rack HIGH 7.5
CVE-2026-34826

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header wi…

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Rack HIGH 7.5
CVE-2026-34230

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding …

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Suricata HIGH 7.5
CVE-2026-31935

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exh…

Fix: 7.0.15 / 8.0.4+
Fix from $1,950 2026-04-02
Stb Vorbis.c MEDIUM 6.5
CVE-2026-5316

A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation…

Fix: after 1.22
Fix from $1,600 2026-04-02
Aiohttp HIGH 7.5
CVE-2026-22815

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer …

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Onnx HIGH 8.6
CVE-2026-34445

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in…

Fix: 1.21.0+
Fix from $1,950 2026-04-01
Og Image HIGH 7.5
CVE-2026-34404

Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in old…

Fix: 6.2.5+
Fix from $1,950 2026-03-31
Serialize HIGH 7.5
CVE-2026-34043

Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS…

Fix: 7.0.5+
Fix from $1,950 2026-03-31
Brace Expansion HIGH 7.5
CVE-2026-33750

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a b…

Fix: 1.1.13 / 2.0.3+
Fix from $1,950 2026-03-27
Grafana MEDIUM 6.5
CVE-2026-27879

A resample query can be used to trigger out-of-memory crashes in Grafana.

Fix: 8.0.0 / 12.0.0+
Fix from $1,600 2026-03-27
Grafana MEDIUM 6.5
CVE-2026-28375

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

Fix: 8.1.0 / 12.0.0+
Fix from $1,600 2026-03-27
Dovecot HIGH 7.5
CVE-2026-27858

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can for…

Fix: 2.3.22.1 / 2.4.3+
Fix from $1,950 2026-03-27
Dovecot MEDIUM 5.3
CVE-2026-27859

A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail…

Fix: 2.4.3 / 3.0.5+
Fix from $1,600 2026-03-27
Dovecot HIGH 7.5
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnec…

Fix: 2.3.22.1 / 2.4.3+
Fix from $1,950 2026-03-27
Pinchtab HIGH 7.2
CVE-2026-33623

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a Windows-only command inj…

Fix: 0.8.5+
Fix from $1,950 2026-03-26
Grafana MEDIUM 6.5
CVE-2026-33375

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catast…

Fix: 11.6.14 / 12.1.10+
Fix from $1,600 2026-03-26
Tsportal MEDIUM 6.5
CVE-2026-33541

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparenc…

Fix: 34+
Fix from $1,600 2026-03-26
Path To Regexp HIGH 7.5
CVE-2026-4926

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The…

Fix: 8.4.0+
Fix from $1,950 2026-03-26