Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified HIGH 7.1
CVE-2026-39959

Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to malicious D-Bus peers. A peer …

Mitigation only
Fix from $1,950 2026-04-09
Orthanc HIGH 7.5
CVE-2026-5440

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directl…

Fix: 1.12.11+
Fix from $1,950 2026-04-09
Orthanc HIGH 7.5
CVE-2026-5438

A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits …

Fix: 1.12.11+
Fix from $1,950 2026-04-09
Orthanc HIGH 7.5
CVE-2026-5439

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and tru…

Fix: 1.12.11+
Fix from $1,950 2026-04-09
Mattermost MEDIUM 6.5
CVE-2026-24661

Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker…

Fix: 2.3.2.0+
Fix from $1,600 2026-04-09
Mattermost Server MEDIUM 6.5
CVE-2026-21388

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker…

Fix: after 2.3.1
Fix from $1,600 2026-04-09
Unfurl HIGH 7.5
CVE-2026-40036

Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of s…

Fix: 2026.04+
Fix from $1,950 2026-04-08
Minio MEDIUM 6.5
CVE-2026-39414

MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO's S3 Select featur…

Fix: after 2025-10-15t17-29-55z
Fix from $1,600 2026-04-08
Unclassified HIGH 7.5
CVE-2026-23869

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turb…

Mitigation only
Fix from $1,950 2026-04-08
Saleor HIGH 7.5
CVE-2026-35401

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations…

Fix: 3.20.118 / 3.21.54+
Fix from $1,950 2026-04-08
Saleor HIGH 7.5
CVE-2026-33756

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multipl…

Fix: 3.20.118 / 3.21.54+
Fix from $1,950 2026-04-08
Go HIGH 7.5
CVE-2026-32280

During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in Verify…

Fix: 1.25.9 / 1.26.2+
Fix from $1,950 2026-04-08
Go HIGH 7.5
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontro…

Fix: 1.25.9 / 1.26.2+
Fix from $1,950 2026-04-08
Go MEDIUM 5.5
CVE-2026-32288

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded …

Fix: 1.25.9 / 1.26.2+
Fix from $1,600 2026-04-08
Podman Desktop CRITICAL 9.1
CVE-2026-34045

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des…

Fix: 1.26.2+
Fix from $2,300 2026-04-07
Opentelemetry HIGH 7.5
CVE-2026-29181

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-va…

Fix: 1.41.0+
Fix from $1,950 2026-04-07
Unclassified MEDIUM 5.3
CVE-2026-5762

Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This…

Mitigation only
Fix from $1,600 2026-04-07
Strawberry Graphql HIGH 7.5
CVE-2026-35526

Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphq…

Fix: 0.312.3+
Fix from $1,950 2026-04-07
Go Ipld Prime MEDIUM 6.2
CVE-2026-35480

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C…

Fix: 0.22.0+
Fix from $1,600 2026-04-07
Libp2p HIGH 7.5
CVE-2026-35405

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on ho…

Fix: 0.17.1+
Fix from $1,950 2026-04-07
Libp2p HIGH 8.2
CVE-2026-35457

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination coo…

Fix: 0.17.1+
Fix from $1,950 2026-04-07
Django HIGH 7.5
CVE-2026-33034

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` h…

Fix: 4.2.30 / 5.2.13+
Fix from $1,950 2026-04-07
Mt6813 Firmware MEDIUM 6.5
CVE-2026-20431

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base s…

Mitigation only
Fix from $1,600 2026-04-07
Directus MEDIUM 6.5
CVE-2026-35441

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql…

Fix: 11.17.0+
Fix from $1,600 2026-04-06
Vllm MEDIUM 6.5
CVE-2026-34755

vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/…

Fix: 0.19.0+
Fix from $1,600 2026-04-06
Vllm MEDIUM 6.5
CVE-2026-34756

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in th…

Fix: 0.19.0+
Fix from $1,600 2026-04-06
Fedify\/fedify HIGH 7.5
CVE-2026-34148

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify fo…

Fix: 1.9.6 / 1.10.5+
Fix from $1,950 2026-04-06
Mesop HIGH 7.5
CVE-2026-34824

Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resourc…

Fix: 1.2.5+
Fix from $1,950 2026-04-03
Lti Jupyterhub Authenticator MEDIUM 5.9
CVE-2026-34052

LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-leve…

Fix: 1.6.3+
Fix from $1,600 2026-04-03
Athena Odbc HIGH 7.5
CVE-2026-35562

Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a de…

Fix: 2.1.0.0+
Fix from $1,950 2026-04-03