Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 6.5 CVE-2026-32588 Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes. Users … Cassandra 4.0.20 / 4.1.11+ Fix from $1,6002026-04-07 MEDIUM 6.5 CVE-2026-35441 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql… Directus 11.17.0+ Fix from $1,6002026-04-06 HIGH 7.5 CVE-2025-54324 An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1… Exynos 990 Firmware Mitigation only Fix from $1,9502026-04-06 CRITICAL 9.1 CVE-2025-58349 An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14… Exynos 990 Firmware Mitigation only Fix from $2,3002026-04-06 MEDIUM 6.2 CVE-2026-0049 In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local … Android Mitigation only Fix from $1,6002026-04-06 HIGH 7.5 CVE-2025-59440 An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, … Exynos 990 Firmware Mitigation only Fix from $1,9502026-04-06 HIGH 7.5 CVE-2026-34148 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify fo… Fedify\/fedify 1.9.6 / 1.10.5+ Fix from $1,9502026-04-06 HIGH 7.5 CVE-2022-4986 Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establ… Eaglesdv Firmware 05.4.02+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2024-14033 Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. Attackers can crash the device… Mitigation only Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-34827 Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mi… Rack 3.1.21 / 3.2.6+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-34593 Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 uncondit… Ash Framework 3.22.0+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-34829 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a Bo… Rack 2.2.23 / 3.1.21+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-34826 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header wi… Rack 2.2.23 / 3.1.21+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-34230 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding … Rack 2.2.23 / 3.1.21+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-31935 Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exh… Suricata 7.0.15 / 8.0.4+ Fix from $1,9502026-04-02 MEDIUM 6.5 CVE-2026-5316 A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation… Stb Vorbis.c after 1.22 Fix from $1,6002026-04-02 HIGH 7.5 CVE-2026-22815 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer … Aiohttp 3.13.4+ Fix from $1,9502026-04-01 HIGH 8.6 CVE-2026-34445 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in… Onnx 1.21.0+ Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-34404 Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in old… Og Image 6.2.5+ Fix from $1,9502026-03-31 HIGH 7.5 CVE-2026-34043 Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS… Serialize 7.0.5+ Fix from $1,9502026-03-31 HIGH 7.5 CVE-2026-33750 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a b… Brace Expansion 1.1.13 / 2.0.3+ Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2026-27879 A resample query can be used to trigger out-of-memory crashes in Grafana. Grafana 8.0.0 / 12.0.0+ Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-28375 A testdata data-source can be used to trigger out-of-memory crashes in Grafana. Grafana 8.1.0 / 12.0.0+ Fix from $1,6002026-03-27 HIGH 7.5 CVE-2026-27858 Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can for… Dovecot 2.3.22.1 / 2.4.3+ Fix from $1,9502026-03-27 MEDIUM 5.3 CVE-2026-27859 A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail… Dovecot 2.4.3 / 3.0.5+ Fix from $1,6002026-03-27 HIGH 7.5 CVE-2026-27857 Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnec… Dovecot 2.3.22.1 / 2.4.3+ Fix from $1,9502026-03-27 HIGH 7.2 CVE-2026-33623 PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a Windows-only command inj… Pinchtab 0.8.5+ Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-33375 The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catast… Grafana 11.6.14 / 12.1.10+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33541 TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparenc… Tsportal 34+ Fix from $1,6002026-03-26 HIGH 7.5 CVE-2026-4926 Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The… Path To Regexp 8.4.0+ Fix from $1,9502026-03-26