Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-0599EPSS 22% A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fe… Patch available Fix from $1,9502026-02-02 HIGH 7.5 CVE-2025-70999 A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (D… Oneflow No fix yet Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-71000 An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. Oneflow No fix yet Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-65891 A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties()… Oneflow No fix yet Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-65886 A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes. Oneflow No fix yet Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-65888 A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or exce… Oneflow No fix yet Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-65889 A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. Oneflow No fix yet Fix from $1,9502026-01-28 HIGH 7.5 CVE-2025-65890 A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid … Oneflow No fix yet Fix from $1,9502026-01-28 MEDIUM 6.5 CVE-2026-24738 gmrtd is a Go library for reading Machine Readable Travel Documents (MRTDs). Prior to version 0.17.2, ReadFile accepts TLVs with lengths that can ran… Gmrtd 0.17.2+ Fix from $1,6002026-01-27 HIGH 7.5 CVE-2026-22258 Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o l… Suricata 7.0.14 / 8.0.3+ Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-22259 Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amou… Suricata 7.0.14 / 8.0.3+ Fix from $1,9502026-01-27 HIGH 7.5 CVE-2025-55102 A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of … Threadx Netx Duo 6.4.5.202504+ Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-21720 Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer tha… Grafana 11.6.9 / 12.0.8+ Fix from $1,9502026-01-27 HIGH 7.5 CVE-2025-59472 A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume end… Next.js 15.6.0 / 16.1.5+ Fix from $1,9502026-01-26 HIGH 7.5 CVE-2025-59471 A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image… Next.js 15.5.10 / 16.1.5+ Fix from $1,9502026-01-26 HIGH 7.5 CVE-2026-23864 Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-… React 19.0.4 / 19.1.5+ Fix from $1,9502026-01-26 HIGH 7.5 CVE-2026-24001 jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename… Jsdiff 3.5.1 / 4.0.4+ Fix from $1,9502026-01-22 HIGH 7.5 CVE-2025-66959 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder Ollama No fix yet Fix from $1,9502026-01-21 HIGH 7.5 CVE-2025-66960 An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string … Ollama No fix yet Fix from $1,9502026-01-21 MEDIUM 5.3 CVE-2026-20080 A vulnerability in the SSH service of Cisco IEC6400 Wireless Backhaul Edge Compute Software could allow an unauthenticated, remote attacker to cause … Mitigation only Fix from $1,6002026-01-21 HIGH 8.2 CVE-2026-21955 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7… Vm Virtualbox Mitigation only Fix from $1,9502026-01-20 HIGH 8.2 CVE-2026-21956 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7… Vm Virtualbox Mitigation only Fix from $1,9502026-01-20 MEDIUM 5.0 CVE-2026-21942 Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). Supported versions that are affected are 10 and 11. Easily … Solaris Mitigation only Fix from $1,6002026-01-20 HIGH 7.5 CVE-2026-21945 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supp… Graalvm Mitigation only Fix from $1,9502026-01-20 MEDIUM 6.5 CVE-2026-21949 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easi… Mysql Server after 9.5.0 Fix from $1,6002026-01-20 MEDIUM 6.5 CVE-2026-21950 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.5.0. Easi… Mysql Server after 9.5.0 Fix from $1,6002026-01-20 HIGH 7.5 CVE-2026-21637 A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are i… Node.js 20.20.0 / 22.22.0+ Fix from $1,9502026-01-20 HIGH 7.5 CVE-2025-59465 A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECON… Node.js 20.20.0 / 22.22.0+ Fix from $1,9502026-01-20 HIGH 7.5 CVE-2025-59464 A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When … Node.js 24.12.0+ Fix from $1,9502026-01-20 HIGH 7.5 CVE-2025-9466 A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP … Armorstart Lt Firmware after 2.002 Fix from $1,9502026-01-20