Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Nimiq Proof Of Stake HIGH 7.5
CVE-2026-34063

Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `Connectio…

Fix: 1.3.0+
Fix from $1,950 2026-04-22
Linux Kernel MEDIUM 5.5
CVE-2026-31451

In the Linux kernel, the following vulnerability has been resolved: ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio Repla…

Fix: 6.6.131 / 6.12.80+
Fix from $1,600 2026-04-22
Nimiq Proof Of Stake MEDIUM 5.3
CVE-2026-34069

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 a…

Fix: 1.3.0+
Fix from $1,600 2026-04-14
Linux Kernel MEDIUM 5.5
CVE-2026-31415

In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6_datagram_send_ctl() Yiming Qian reported : <quote>…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-04-13
Avahi MEDIUM 5.5
CVE-2026-34933

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileg…

Fix: 0.9+
Fix from $1,600 2026-04-03
Linux Kernel HIGH 7.8
CVE-2026-31398

In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix incorrect pte restoration for lazyfree folios We batch unmap anony…

Fix: 6.18.20 / 6.19.10+
Fix from $1,950 2026-04-03
Cocoamqtt MEDIUM 6.5
CVE-2026-30867

CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic…

Fix: 2.2.2+
Fix from $1,600 2026-04-02
Libp2p Gossipsub MEDIUM 5.9
CVE-2026-34219

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implement…

Fix: 0.49.4+
Fix from $1,600 2026-03-31
Freerdp MEDIUM 6.5
CVE-2026-33977

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can crash the FreeRDP client by send…

Fix: 3.24.2+
Fix from $1,600 2026-03-30
Freerdp MEDIUM 6.5
CVE-2026-33952

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length field read from the network trig…

Fix: 3.24.2+
Fix from $1,600 2026-03-30
Glibc HIGH 7.5
CVE-2026-4046

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or …

Fix: after 2.43
Fix from $1,950 2026-03-30
MongoDB MEDIUM 5.3
CVE-2026-5170

A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during the limited and unpredictabl…

Fix: 7.0.31 / 8.0.18+
Fix from $1,600 2026-03-30
Bind MEDIUM 6.5
CVE-2026-3119

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached …

Fix: 9.20.21 / 9.21.20+
Fix from $1,600 2026-03-25
Linux Kernel MEDIUM 5.5
CVE-2026-23380

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close When a process forks, the ch…

Fix: 6.12.77 / 6.18.17+
Fix from $1,600 2026-03-25
Linux Kernel MEDIUM 5.5
CVE-2026-23375

In the Linux kernel, the following vulnerability has been resolved: mm: thp: deny THP for files on anonymous inodes file_thp_enabled() incorrectly …

Fix: 6.12.78 / 6.18.17+
Fix from $1,600 2026-03-25
Linux Kernel MEDIUM 5.5
CVE-2026-23356

In the Linux kernel, the following vulnerability has been resolved: drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock() Even though we check that …

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-03-25
Unclassified HIGH 7.5
CVE-2026-3608

Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA list…

Mitigation only
Fix from $1,950 2026-03-25
Xen HIGH 7.1
CVE-2026-23555

Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error i…

Patch available
Fix from $1,950 2026-03-23
Nghttp2 HIGH 7.5
CVE-2026-27135

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incomi…

Fix: 1.68.1+
Fix from $1,950 2026-03-18
Quickjs MEDIUM 6.5
CVE-2025-69653

A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb…

Fix: 2025-12-11+
Fix from $1,600 2026-03-06
Markdown HIGH 7.5
CVE-2025-69534

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled Assert…

No fix yet
Fix from $1,950 2026-03-05
Linux Kernel MEDIUM 5.5
CVE-2026-23238

In the Linux kernel, the following vulnerability has been resolved: romfs: check sb_set_blocksize() return value romfs_fill_super() ignores the ret…

Fix: 5.10.251 / 5.15.201+
Fix from $1,600 2026-03-04
5g Fixed Wireless Access Platform Firmware MEDIUM 6.5
CVE-2025-47384

Transient DOS when MAC configures config id greater than supported maximum value.

No fix yet
Fix from $1,600 2026-03-02
5g Fixed Wireless Access Platform Firmware MEDIUM 6.5
CVE-2025-47371

Transient DOS when an LTE RLC packet with invalid TB is received by UE.

Mitigation only
Fix from $1,600 2026-03-02
Psd Tools CRITICAL 9.1
CVE-2026-27809

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed …

Fix: 1.12.2+
Fix from $2,300 2026-02-26
Freerdp MEDIUM 6.5
CVE-2026-27015

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align…

Fix: 3.23.0+
Fix from $1,600 2026-02-25
Valkey HIGH 7.5
CVE-2026-27623

Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can…

Fix: 9.0.3+
Fix from $1,950 2026-02-23
Open5gs HIGH 7.5
CVE-2026-2523

A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_context_request of the file /src/s…

Fix: after 2.7.6
Fix from $1,950 2026-02-16
Vnet\/ip Interface Package MEDIUM 6.5
CVE-2025-48023

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously craft…

Mitigation only
Fix from $1,600 2026-02-13
Vnet\/ip Interface Package MEDIUM 6.5
CVE-2025-48019

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously craft…

Mitigation only
Fix from $1,600 2026-02-13