Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Unclassified HIGH 7.5
CVE-2026-52829

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node usin…

Fix unknown
Fix from $4,900 2026-08-18
Ipados MEDIUM 6.5
CVE-2026-43667

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privilege…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.3
CVE-2025-15684

A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/common/init.c of the component C…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-18695

An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-18697

An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly …

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.2
CVE-2026-71430

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-52856

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received dur…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.9
CVE-2026-66754

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated at…

No fix yet
Fix from $1,600 2026-07-28
Hdf5 MEDIUM 5.5
CVE-2026-17574

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length dataty…

No fix yet
Fix from $1,600 2026-07-27
Linux Kernel MEDIUM 5.5
CVE-2026-64254

In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR W…

Fix: 6.1.177 / 6.6.144+
Fix from $1,600 2026-07-24
Nimble HIGH 7.5
CVE-2026-45815

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigge…

Fix: 1.10.0+
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-9737

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may…

No fix yet
Fix from $1,600 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13055

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to han…

Fix: 7.0.39 / 8.0.28+
Fix from $1,600 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13058

An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with …

Fix: 8.0.28 / 8.2.12+
Fix from $1,600 2026-07-22
Unclassified HIGH 7.5
CVE-2026-13204

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B…

No fix yet
Fix from $1,950 2026-07-22
Unclassified MEDIUM 6.5
CVE-2026-10822

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND w…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 7.5
CVE-2026-12617

The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Spec…

No fix yet
Fix from $1,950 2026-07-22
Unclassified MEDIUM 5.9
CVE-2026-14586

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in lib…

No fix yet
Fix from $1,600 2026-07-22
Zephyr MEDIUM 5.5
CVE-2026-10674

The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, called LPUART_Deinit() at the st…

Fix: after 4.4.1
Fix from $1,600 2026-07-21
Elasticsearch MEDIUM 6.5
CVE-2026-63140

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search requ…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Linux Kernel HIGH 7.1
CVE-2026-63806

In the Linux kernel, the following vulnerability has been resolved: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligne…

Fix: 5.10.261 / 5.15.212+
Fix from $1,950 2026-07-19
Quicly HIGH 7.5
CVE-2026-44435

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure i…

Fix: 2026-05-29+
Fix from $1,950 2026-07-16
Matter HIGH 7.5
CVE-2025-56362

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic…

Mitigation only
Fix from $1,950 2026-07-14
Matter HIGH 7.5
CVE-2025-56365

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When …

Fix: 1.4.0.0+
Fix from $1,950 2026-07-14
Matter HIGH 7.5
CVE-2025-56361

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server t…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.2
CVE-2026-47475

NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the samp…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.1
CVE-2026-58307

Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue a…

Patch available
Fix from $1,600 2026-07-09
Vllm MEDIUM 6.5
CVE-2026-55514

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with…

Fix: 0.24.0+
Fix from $1,600 2026-07-06
Openvpn MEDIUM 5.3
CVE-2026-13122

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication…

Fix: 2.6.21 / 2.7.5+
Fix from $1,600 2026-07-06
Libreswan MEDIUM 5.9
CVE-2026-50721

Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG pa…

Fix: 5.3.1+
Fix from $1,600 2026-07-02