Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified HIGH 7.5
CVE-2026-0599EPSS 22%

A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fe…

Patch available
Fix from $1,950 2026-02-02
Oneflow HIGH 7.5
CVE-2025-70999

A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (D…

No fix yet
Fix from $1,950 2026-01-28
Oneflow HIGH 7.5
CVE-2025-71000

An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

No fix yet
Fix from $1,950 2026-01-28
Oneflow HIGH 7.5
CVE-2025-65891

A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties()…

No fix yet
Fix from $1,950 2026-01-28
Oneflow HIGH 7.5
CVE-2025-65886

A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes.

No fix yet
Fix from $1,950 2026-01-28
Oneflow HIGH 7.5
CVE-2025-65888

A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or exce…

No fix yet
Fix from $1,950 2026-01-28
Oneflow HIGH 7.5
CVE-2025-65889

A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

No fix yet
Fix from $1,950 2026-01-28
Oneflow HIGH 7.5
CVE-2025-65890

A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid …

No fix yet
Fix from $1,950 2026-01-28
Gmrtd MEDIUM 6.5
CVE-2026-24738

gmrtd is a Go library for reading Machine Readable Travel Documents (MRTDs). Prior to version 0.17.2, ReadFile accepts TLVs with lengths that can ran…

Fix: 0.17.2+
Fix from $1,600 2026-01-27
Suricata HIGH 7.5
CVE-2026-22258

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o l…

Fix: 7.0.14 / 8.0.3+
Fix from $1,950 2026-01-27
Suricata HIGH 7.5
CVE-2026-22259

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amou…

Fix: 7.0.14 / 8.0.3+
Fix from $1,950 2026-01-27
Threadx Netx Duo HIGH 7.5
CVE-2025-55102

A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of …

Fix: 6.4.5.202504+
Fix from $1,950 2026-01-27
Grafana HIGH 7.5
CVE-2026-21720

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer tha…

Fix: 11.6.9 / 12.0.8+
Fix from $1,950 2026-01-27
Next.js HIGH 7.5
CVE-2025-59472

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume end…

Fix: 15.6.0 / 16.1.5+
Fix from $1,950 2026-01-26
Next.js HIGH 7.5
CVE-2025-59471

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image…

Fix: 15.5.10 / 16.1.5+
Fix from $1,950 2026-01-26
React HIGH 7.5
CVE-2026-23864

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-…

Fix: 19.0.4 / 19.1.5+
Fix from $1,950 2026-01-26
Jsdiff HIGH 7.5
CVE-2026-24001

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename…

Fix: 3.5.1 / 4.0.4+
Fix from $1,950 2026-01-22
Ollama HIGH 7.5
CVE-2025-66959

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder

No fix yet
Fix from $1,950 2026-01-21
Ollama HIGH 7.5
CVE-2025-66960

An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string …

No fix yet
Fix from $1,950 2026-01-21
Unclassified MEDIUM 5.3
CVE-2026-20080

A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause …

Mitigation only
Fix from $1,600 2026-01-21
Vm Virtualbox HIGH 8.2
CVE-2026-21955

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…

Mitigation only
Fix from $1,950 2026-01-20
Vm Virtualbox HIGH 8.2
CVE-2026-21956

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…

Mitigation only
Fix from $1,950 2026-01-20
Solaris MEDIUM 5.0
CVE-2026-21942

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are affected are 10 and 11. Easily …

Mitigation only
Fix from $1,600 2026-01-20
Graalvm HIGH 7.5
CVE-2026-21945

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp…

Mitigation only
Fix from $1,950 2026-01-20
Mysql Server MEDIUM 6.5
CVE-2026-21949

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easi…

Fix: after 9.5.0
Fix from $1,600 2026-01-20
Mysql Server MEDIUM 6.5
CVE-2026-21950

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easi…

Fix: after 9.5.0
Fix from $1,600 2026-01-20
Node.js HIGH 7.5
CVE-2026-21637

A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are i…

Fix: 20.20.0 / 22.22.0+
Fix from $1,950 2026-01-20
Node.js HIGH 7.5
CVE-2025-59465

A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECON…

Fix: 20.20.0 / 22.22.0+
Fix from $1,950 2026-01-20
Node.js HIGH 7.5
CVE-2025-59464

A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When …

Fix: 24.12.0+
Fix from $1,950 2026-01-20
Armorstart Lt Firmware HIGH 7.5
CVE-2025-9466

A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP …

Fix: after 2.002
Fix from $1,950 2026-01-20