Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
HIGH 7.5 CVE-2026-52829 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node usin… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-43667 A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privilege… Ipados Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.3 CVE-2025-15684 A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/common/init.c of the component C… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-18695 An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user … No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-18697 An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly … No fix yet Fix from $4,9002026-08-11 MEDIUM 6.2 CVE-2026-71430 node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-52856 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received dur… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.9 CVE-2026-66754 Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated at… No fix yet Fix from $1,6002026-07-28 MEDIUM 5.5 CVE-2026-17574 HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length dataty… Hdf5 No fix yet Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-64254 In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR W… Linux Kernel 6.1.177 / 6.6.144+ Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-45815 Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigge… Nimble 1.10.0+ Fix from $1,9502026-07-24 MEDIUM 6.5 CVE-2026-9737 During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may… No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-13055 The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to han… MongoDB 7.0.39 / 8.0.28+ Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-13058 An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with … MongoDB 8.0.28 / 8.2.12+ Fix from $1,6002026-07-22 HIGH 7.5 CVE-2026-13204 If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B… No fix yet Fix from $1,9502026-07-22 MEDIUM 6.5 CVE-2026-10822 If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND w… No fix yet Fix from $1,6002026-07-22 HIGH 7.5 CVE-2026-12617 The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Spec… No fix yet Fix from $1,9502026-07-22 MEDIUM 5.9 CVE-2026-14586 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in lib… No fix yet Fix from $1,6002026-07-22 MEDIUM 5.5 CVE-2026-10674 The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, called LPUART_Deinit() at the st… Zephyr after 4.4.1 Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-63140 Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search requ… Elasticsearch 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 HIGH 7.1 CVE-2026-63806 In the Linux kernel, the following vulnerability has been resolved: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligne… Linux Kernel 5.10.261 / 5.15.212+ Fix from $1,9502026-07-19 HIGH 7.5 CVE-2026-44435 Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure i… Quicly 2026-05-29+ Fix from $1,9502026-07-16 HIGH 7.5 CVE-2025-56362 A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic… Matter Mitigation only Fix from $1,9502026-07-14 HIGH 7.5 CVE-2025-56365 A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When … Matter 1.4.0.0+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2025-56361 A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server t… Matter Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.2 CVE-2026-47475 NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the samp… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-58307 Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue a… Patch available Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-55514 vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with… Vllm 0.24.0+ Fix from $1,6002026-07-06 MEDIUM 5.3 CVE-2026-13122 OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication… Openvpn 2.6.21 / 2.7.5+ Fix from $1,6002026-07-06 MEDIUM 5.9 CVE-2026-50721 Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG pa… Libreswan 5.3.1+ Fix from $1,6002026-07-02