Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Liquidjs HIGH 7.5
CVE-2026-33285

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mecha…

Fix: 10.25.1+
Fix from $1,950 2026-03-26
Liquidjs HIGH 7.5
CVE-2026-33287

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS …

Fix: 10.25.1+
Fix from $1,950 2026-03-26
Mattermost Server MEDIUM 6.5
CVE-2026-26233

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthen…

Fix: 10.11.12 / 11.2.4+
Fix from $1,600 2026-03-25
Unclassified HIGH 8.6
CVE-2026-20084

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be fo…

Mitigation only
Fix from $1,950 2026-03-25
Unclassified MEDIUM 6.5
CVE-2026-33268

Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and con…

Mitigation only
Fix from $1,600 2026-03-25
Ipados HIGH 7.5
CVE-2026-28874

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected app terminat…

Fix: 26.4+
Fix from $1,950 2026-03-25
Parse Server HIGH 7.5
CVE-2026-33538

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.58 and 9.6.0-alpha.52, …

Fix: 8.6.58 / 9.6.0+
Fix from $1,950 2026-03-24
Vikunja MEDIUM 6.5
CVE-2026-33474

Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0, unbounded image decoding an…

Fix: 2.2.0+
Fix from $1,600 2026-03-24
Free5gc HIGH 7.5
CVE-2026-30653

An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuthenticationFailure of the comp…

Fix: after 4.2.0
Fix from $1,950 2026-03-24
Concrete Cms MEDIUM 6.5
CVE-2026-30662

ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/bac…

No fix yet
Fix from $1,600 2026-03-24
Firefox HIGH 7.5
CVE-2026-4726

Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4727

Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Fix: 149.0+
Fix from $1,950 2026-03-24
Firefox HIGH 7.5
CVE-2026-4704

Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbir…

Fix: 140.9.0 / 149.0+
Fix from $1,950 2026-03-24
Rails MEDIUM 5.3
CVE-2026-33169

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a loo…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,600 2026-03-24
Rails HIGH 7.5
CVE-2026-33176

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,950 2026-03-24
Simplejwt HIGH 7.5
CVE-2026-33204

SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via …

Fix: 1.1.1+
Fix from $1,950 2026-03-20
Deepdiff HIGH 7.5
CVE-2026-33155

DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _Res…

Fix: 8.6.2+
Fix from $1,950 2026-03-20
Pypdf MEDIUM 6.5
CVE-2026-33123

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runti…

Fix: 6.9.1+
Fix from $1,600 2026-03-20
.net HIGH 7.5
CVE-2026-25667

ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by se…

Fix: 8.0.22 / 9.0.11+
Fix from $1,950 2026-03-19
Aapanel HIGH 7.5
CVE-2026-29856

An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Servi…

No fix yet
Fix from $1,950 2026-03-18
Next.js HIGH 7.5
CVE-2026-27980

Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js im…

Fix: 16.1.7+
Fix from $1,950 2026-03-18
Wazuh HIGH 7.5
CVE-2026-25771

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 and prior to version 4.14.3, …

Fix: 4.14.3+
Fix from $1,950 2026-03-17
Unclassified MEDIUM 6.5
CVE-2025-68971

In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated …

Mitigation only
Fix from $1,600 2026-03-16
Gobgp HIGH 7.5
CVE-2026-30405

An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute

No fix yet
Fix from $1,950 2026-03-16
Aion HIGH 7.5
CVE-2025-52636

HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow exces…

Fix: 2.1.2+
Fix from $1,950 2026-03-16
Gokapi MEDIUM 6.5
CVE-2026-30955

Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded reque…

Fix: 2.2.4+
Fix from $1,600 2026-03-13
Unclassified HIGH 7.5
CVE-2026-25819

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unau…

Mitigation only
Fix from $1,950 2026-03-13
Hexpm MEDIUM 6.5
CVE-2026-23940

Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversized package can cause Hex.pm to…

Fix: 2026-03-09+
Fix from $1,600 2026-03-13
Tornado HIGH 7.5
CVE-2026-31958

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts i…

Fix: 6.5.5+
Fix from $1,950 2026-03-11
Iccdev MEDIUM 5.5
CVE-2026-30980

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack overflow in CIccBasic…

Fix: 2.3.1.5+
Fix from $1,600 2026-03-10