Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-33285 LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mecha… Liquidjs 10.25.1+ Fix from $1,9502026-03-26 HIGH 7.5 CVE-2026-33287 LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `replace_first` filter in LiquidJS … Liquidjs 10.25.1+ Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-26233 Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthen… Mattermost Server 10.11.12 / 11.2.4+ Fix from $1,6002026-03-25 HIGH 8.6 CVE-2026-20084 A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be fo… Mitigation only Fix from $1,9502026-03-25 MEDIUM 6.5 CVE-2026-33268 Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmware files on the device and con… Mitigation only Fix from $1,6002026-03-25 HIGH 7.5 CVE-2026-28874 The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected app terminat… Ipados 26.4+ Fix from $1,9502026-03-25 HIGH 7.5 CVE-2026-33538 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.58 and 9.6.0-alpha.52, … Parse Server 8.6.58 / 9.6.0+ Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-33474 Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0, unbounded image decoding an… Vikunja 2.2.0+ Fix from $1,6002026-03-24 HIGH 7.5 CVE-2026-30653 An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuthenticationFailure of the comp… Free5gc after 4.2.0 Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-30662 ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method in 'concrete/controllers/bac… Concrete Cms No fix yet Fix from $1,6002026-03-24 HIGH 7.5 CVE-2026-4726 Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4727 Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149. Firefox 149.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-4704 Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbir… Firefox 140.9.0 / 149.0+ Fix from $1,9502026-03-24 MEDIUM 5.3 CVE-2026-33169 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToDelimitedConverter` uses a loo… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,6002026-03-24 HIGH 7.5 CVE-2026-33176 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33204 SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can perform a Denial of Service via … Simplejwt 1.1.1+ Fix from $1,9502026-03-20 HIGH 7.5 CVE-2026-33155 DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _Res… Deepdiff 8.6.2+ Fix from $1,9502026-03-20 MEDIUM 6.5 CVE-2026-33123 pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runti… Pypdf 6.9.1+ Fix from $1,6002026-03-20 HIGH 7.5 CVE-2026-25667 ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by se… .net 8.0.22 / 9.0.11+ Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-29856 An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regular Expression Denial of Servi… Aapanel No fix yet Fix from $1,9502026-03-18 HIGH 7.5 CVE-2026-27980 Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js im… Next.js 16.1.7+ Fix from $1,9502026-03-18 HIGH 7.5 CVE-2026-25771 Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 and prior to version 4.14.3, … Wazuh 4.14.3+ Fix from $1,9502026-03-17 MEDIUM 6.5 CVE-2025-68971 In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated … Mitigation only Fix from $1,6002026-03-16 HIGH 7.5 CVE-2026-30405 An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute Gobgp No fix yet Fix from $1,9502026-03-16 HIGH 7.5 CVE-2025-52636 HCL AION is affected by a vulnerability related to the handling of upload size limits. Improper control or validation of upload sizes may allow exces… Aion 2.1.2+ Fix from $1,9502026-03-16 MEDIUM 6.5 CVE-2026-30955 Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded reque… Gokapi 2.2.4+ Fix from $1,6002026-03-13 HIGH 7.5 CVE-2026-25819 HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 allows unau… Mitigation only Fix from $1,9502026-03-13 MEDIUM 6.5 CVE-2026-23940 Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversized package can cause Hex.pm to… Hexpm 2026-03-09+ Fix from $1,6002026-03-13 HIGH 7.5 CVE-2026-31958 Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts i… Tornado 6.5.5+ Fix from $1,9502026-03-11 MEDIUM 5.5 CVE-2026-30980 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack overflow in CIccBasic… Iccdev 2.3.1.5+ Fix from $1,6002026-03-10