Vulnerability index

Browse CVEs

1,782 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory LeakCWE-401 × clear
Unclassified MEDIUM 5.3
CVE-2026-52734

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transac…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-73565

@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route w…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-56818

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec c…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.5
CVE-2026-54876

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response tha…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.4
CVE-2026-51400

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/sr…

No fix yet
Fix from $1,950 2026-08-04
Milo HIGH 7.5
CVE-2026-63252

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnec…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Zephyr MEDIUM 6.5
CVE-2026-10774

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys…

Fix: 4.5.0+
Fix from $1,600 2026-08-02
Openvpn HIGH 8.1
CVE-2026-12932

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause…

Fix: 2.6.21 / 2.7.5+
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-67437

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_au…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-67430

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo…

No fix yet
Fix from $1,600 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58175

Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 …

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Unclassified HIGH 7.5
CVE-2026-67183

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well…

No fix yet
Fix from $1,950 2026-07-28
Linux Kernel MEDIUM 5.5
CVE-2026-64292

In the Linux kernel, the following vulnerability has been resolved: iommufd: Move vevent memory allocation outside spinlock The veventq memory allo…

Fix: 6.18.40 / 7.1.4+
Fix from $1,600 2026-07-25
Linux Kernel MEDIUM 5.5
CVE-2026-64241

In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: teardown bugs and resource leaks Address several teardown issue…

Fix: 6.12.96 / 6.18.35+
Fix from $1,600 2026-07-24
Netty HIGH 7.5
CVE-2026-56819

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Fina…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-21
Zephyr MEDIUM 6.5
CVE-2026-10677

The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_…

Fix: after 4.4.1
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.3
CVE-2026-16318

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.5
CVE-2026-47667

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` f…

No fix yet
Fix from $1,950 2026-07-21
Linux Kernel MEDIUM 5.5
CVE-2026-64179

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: fix potential memory leaks in ipc_imem_init() The memory alloc…

Fix: 5.15.209 / 6.1.175+
Fix from $1,600 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-64161

In the Linux kernel, the following vulnerability has been resolved: net: ti: icssm-prueth: fix eth_ports_node leak in probe The error path on of_pr…

Fix: 6.18.34 / 7.0.11+
Fix from $1,600 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-64155

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix error path leaks in some WMI WOW calls Fix two instances wher…

Fix unknown
Fix from $1,600 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-64144

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: fix urb->setup_packet leak in error paths The setup_packet of…

Fix unknown
Fix from $1,600 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-64146

In the Linux kernel, the following vulnerability has been resolved: erofs: fix metabuf leak in inode xattr initialization commit bb88e8da0025 ("ero…

Fix unknown
Fix from $1,600 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-64147

In the Linux kernel, the following vulnerability has been resolved: pds_core: fix debugfs_lookup dentry leak and error handling debugfs_lookup() re…

Fix unknown
Fix from $1,600 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-64139

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit 2…

Fix unknown
Fix from $1,600 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-64129

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page When c…

Fix: 7.0.11+
Fix from $1,600 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-64110

In the Linux kernel, the following vulnerability has been resolved: igc: fix potential skb leak in igc_fpe_xmit_smd_frame() When igc_fpe_init_tx_de…

Fix: 6.18.34 / 7.0.11+
Fix from $1,600 2026-07-19
Linux Kernel HIGH 8.7
CVE-2026-64104

In the Linux kernel, the following vulnerability has been resolved: virt: sev-guest: Explicitly leak pages in unknown state When set_memory_{encryp…

Fix: 6.14 / 6.18.34+
Fix from $1,950 2026-07-19
Linux Kernel MEDIUM 5.5
CVE-2026-63798

In the Linux kernel, the following vulnerability has been resolved: irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove…

Fix: 5.10.260 / 5.15.211+
Fix from $1,600 2026-07-19
Linux Kernel HIGH 7.5
CVE-2026-53394

In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race When find…

Fix: 6.12.95 / 6.18.38+
Fix from $1,950 2026-07-19