Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Libreswan MEDIUM 5.9
CVE-2026-50722

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the I…

Fix: 5.3.1+
Fix from $1,600 2026-07-02
Libreswan HIGH 7.5
CVE-2026-12413

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service.…

Fix: 5.3.1+
Fix from $1,950 2026-07-02
Linux Kernel MEDIUM 5.5
CVE-2026-53319

In the Linux kernel, the following vulnerability has been resolved: blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default() wbt_init_enable_def…

Fix: 7.0.10+
Fix from $1,600 2026-06-26
Linux Kernel MEDIUM 5.5
CVE-2026-53292

In the Linux kernel, the following vulnerability has been resolved: net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind syzbot repo…

Fix: 7.0.10+
Fix from $1,600 2026-06-26
Linux Kernel MEDIUM 5.5
CVE-2026-53285

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_E…

Fix: 7.0.10+
Fix from $1,600 2026-06-26
Powerlogic P7 Firmware MEDIUM 6.5
CVE-2026-9718

CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting syste…

Fix: 02.004.001.000+
Fix from $1,600 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47145

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a dev…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Emberznet MEDIUM 6.5
CVE-2026-47146

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a dev…

Fix: after 9.0.2
Fix from $1,600 2026-06-25
Linux Kernel MEDIUM 5.5
CVE-2026-53169

In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject NPU_OP_RESIZE commands from userspace NPU_OP_RESIZE is a U…

Fix: 7.0.13+
Fix from $1,600 2026-06-25
Linux Kernel MEDIUM 5.5
CVE-2026-53039

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate group add input before caching [BUG] OCFS2_IOC_GROUP_ADD can tr…

Fix: 5.10.258 / 5.15.209+
Fix from $1,600 2026-06-24
Linux Kernel MEDIUM 5.5
CVE-2026-52961

In the Linux kernel, the following vulnerability has been resolved: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size The gener…

Fix: 6.12.91 / 6.18.33+
Fix from $1,600 2026-06-24
Linux Kernel HIGH 8.8
CVE-2026-52952

In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset In __iommu…

Fix: 7.0.10+
Fix from $1,950 2026-06-24
Linux Kernel HIGH 7.5
CVE-2026-52954

In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_choose_args() A message of typ…

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-06-24
Zephyr MEDIUM 6.5
CVE-2026-10651

bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte a…

Fix: after 4.4.1
Fix from $1,600 2026-06-23
Vllm HIGH 7.5
CVE-2026-41523

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation functi…

Fix: 0.22.0+
Fix from $1,950 2026-06-22
Unclassified MEDIUM 6.5
CVE-2026-52718

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function pas…

Mitigation only
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.9
CVE-2026-29115

A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an …

Mitigation only
Fix from $1,600 2026-06-10
Unclassified HIGH 8.7
CVE-2026-29116

A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering a…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified MEDIUM 5.3
CVE-2026-46543

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer…

Patch available
Fix from $1,600 2026-06-10
MongoDB MEDIUM 6.5
CVE-2026-9747

Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.

Fix: 7.0.35 / 8.0.24+
Fix from $1,600 2026-06-09
MongoDB MEDIUM 6.5
CVE-2026-9748

The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But Pa…

Fix: 7.0.35 / 8.0.10+
Fix from $1,600 2026-06-09
MongoDB MEDIUM 6.5
CVE-2026-9749

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-pre…

Fix: 7.0.35 / 8.0.24+
Fix from $1,600 2026-06-09
MongoDB MEDIUM 6.5
CVE-2026-9750

An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata pro…

Fix: 7.0.35 / 8.0.24+
Fix from $1,600 2026-06-09
MongoDB MEDIUM 6.5
CVE-2026-9746

When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. …

Fix: 7.0.35 / 8.0.24+
Fix from $1,600 2026-06-09
Openvpn MEDIUM 6.5
CVE-2026-35058

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authentic…

Fix: 2.6.20 / 2.7.2+
Fix from $1,600 2026-06-08
Linux Kernel MEDIUM 5.5
CVE-2026-46287

In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix RTNL assertion warning when remove module For the copper NIC wi…

Fix: 6.6.140 / 6.12.88+
Fix from $1,600 2026-06-08
Flexric HIGH 7.5
CVE-2026-37228

FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and …

No fix yet
Fix from $1,950 2026-06-01
Flexric HIGH 7.5
CVE-2026-37229

FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can sen…

No fix yet
Fix from $1,950 2026-06-01
Flexric HIGH 7.5
CVE-2026-37233

FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xa…

No fix yet
Fix from $1,950 2026-06-01
Unclassified HIGH 7.5
CVE-2026-37222

FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can …

Mitigation only
Fix from $1,950 2026-06-01