Vulnerability index

Browse CVEs

1,782 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory LeakCWE-401 × clear
MEDIUM 5.3 CVE-2026-52734 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transac… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-73565 @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route w… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-56818 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec c… No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-54876 Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response tha… No fix yet Fix from $1,9502026-08-05 HIGH 8.4 CVE-2026-51400 An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/sr… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-63252 In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnec… Milo 1.1.5+ Fix from $1,9502026-08-04 MEDIUM 6.5 CVE-2026-10774 Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys… Zephyr 4.5.0+ Fix from $1,6002026-08-02 HIGH 8.1 CVE-2026-12932 A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-67437 OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_au… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-67430 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-58175 Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-67183 TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well… No fix yet Fix from $1,9502026-07-28 MEDIUM 5.5 CVE-2026-64292 In the Linux kernel, the following vulnerability has been resolved: iommufd: Move vevent memory allocation outside spinlock The veventq memory allo… Linux Kernel 6.18.40 / 7.1.4+ Fix from $1,6002026-07-25 MEDIUM 5.5 CVE-2026-64241 In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: teardown bugs and resource leaks Address several teardown issue… Linux Kernel 6.12.96 / 6.18.35+ Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-56819 Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Fina… Netty 4.1.136 / 4.2.16+ Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-10677 The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_… Zephyr after 4.4.1 Fix from $1,6002026-07-21 MEDIUM 5.3 CVE-2026-16318 The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters… No fix yet Fix from $1,6002026-07-21 HIGH 7.5 CVE-2026-47667 CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` f… No fix yet Fix from $1,9502026-07-21 MEDIUM 5.5 CVE-2026-64179 In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: fix potential memory leaks in ipc_imem_init() The memory alloc… Linux Kernel 5.15.209 / 6.1.175+ Fix from $1,6002026-07-19 MEDIUM 5.5 CVE-2026-64161 In the Linux kernel, the following vulnerability has been resolved: net: ti: icssm-prueth: fix eth_ports_node leak in probe The error path on of_pr… Linux Kernel 6.18.34 / 7.0.11+ Fix from $1,6002026-07-19 MEDIUM 5.5 CVE-2026-64155 In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix error path leaks in some WMI WOW calls Fix two instances wher… Linux Kernel Fix unknown Fix from $1,6002026-07-19 MEDIUM 5.5 CVE-2026-64144 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: fix urb->setup_packet leak in error paths The setup_packet of… Linux Kernel Fix unknown Fix from $1,6002026-07-19 MEDIUM 5.5 CVE-2026-64146 In the Linux kernel, the following vulnerability has been resolved: erofs: fix metabuf leak in inode xattr initialization commit bb88e8da0025 ("ero… Linux Kernel Fix unknown Fix from $1,6002026-07-19 MEDIUM 5.5 CVE-2026-64147 In the Linux kernel, the following vulnerability has been resolved: pds_core: fix debugfs_lookup dentry leak and error handling debugfs_lookup() re… Linux Kernel Fix unknown Fix from $1,6002026-07-19 MEDIUM 5.5 CVE-2026-64139 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit 2… Linux Kernel Fix unknown Fix from $1,6002026-07-19 MEDIUM 5.5 CVE-2026-64129 In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page When c… Linux Kernel 7.0.11+ Fix from $1,6002026-07-19 MEDIUM 5.5 CVE-2026-64110 In the Linux kernel, the following vulnerability has been resolved: igc: fix potential skb leak in igc_fpe_xmit_smd_frame() When igc_fpe_init_tx_de… Linux Kernel 6.18.34 / 7.0.11+ Fix from $1,6002026-07-19 HIGH 8.7 CVE-2026-64104 In the Linux kernel, the following vulnerability has been resolved: virt: sev-guest: Explicitly leak pages in unknown state When set_memory_{encryp… Linux Kernel 6.14 / 6.18.34+ Fix from $1,9502026-07-19 MEDIUM 5.5 CVE-2026-63798 In the Linux kernel, the following vulnerability has been resolved: irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove… Linux Kernel 5.10.260 / 5.15.211+ Fix from $1,6002026-07-19 HIGH 7.5 CVE-2026-53394 In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race When find… Linux Kernel 6.12.95 / 6.18.38+ Fix from $1,9502026-07-19