Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Budibase HIGH 7.5
CVE-2026-25043

Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functional…

Fix: 3.23.25+
Fix from $1,950 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23468

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace …

Fix: 6.6.140 / 6.12.86+
Fix from $1,600 2026-04-03
Rack HIGH 7.5
CVE-2026-34827

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mi…

Fix: 3.1.21 / 3.2.6+
Fix from $1,950 2026-04-02
Ash Framework HIGH 7.5
CVE-2026-34593

Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 uncondit…

Fix: 3.22.0+
Fix from $1,950 2026-04-02
Rack HIGH 7.5
CVE-2026-34829

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a Bo…

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Rack HIGH 7.5
CVE-2026-34826

Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header wi…

Fix: 2.2.23 / 3.1.21+
Fix from $1,950 2026-04-02
Suricata HIGH 7.5
CVE-2026-31935

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exh…

Fix: 7.0.15 / 8.0.4+
Fix from $1,950 2026-04-02
Wisp HIGH 7.5
CVE-2026-32145

Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing. Th…

Fix: 2.2.2+
Fix from $1,950 2026-04-02
Stb Vorbis.c MEDIUM 6.5
CVE-2026-5316

A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation…

Fix: after 1.22
Fix from $1,600 2026-04-02
Aspera Shares MEDIUM 6.5
CVE-2025-66487

IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in e…

Fix: 1.11.1+
Fix from $1,600 2026-04-01
Aiohttp HIGH 7.5
CVE-2026-34513

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in exces…

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Aiohttp HIGH 7.5
CVE-2026-34516

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multi…

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Aiohttp MEDIUM 5.3
CVE-2026-34517

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read…

Fix: 3.13.4+
Fix from $1,600 2026-04-01
Aiohttp HIGH 7.5
CVE-2026-22815

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer …

Fix: 3.13.4+
Fix from $1,950 2026-04-01
Go Git MEDIUM 5.0
CVE-2026-34165

go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identifi…

Fix: 5.17.1+
Fix from $1,600 2026-03-31
Node.js HIGH 7.5
CVE-2026-21710EPSS 26%

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application…

Fix: after 25.8.1
Fix from $1,950 2026-03-30
Openclaw HIGH 7.5
CVE-2026-32980

OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing un…

Fix: 2026.3.13+
Fix from $1,950 2026-03-29
Netty HIGH 7.5
CVE-2026-33871

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger …

Fix: 4.1.132 / 4.2.10+
Fix from $1,950 2026-03-27
Fleet HIGH 7.5
CVE-2026-26061

Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies wi…

Fix: 4.81.0+
Fix from $1,950 2026-03-27
Grafana HIGH 7.5
CVE-2026-27880

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

Fix: 12.1.0 / 12.2.0+
Fix from $1,950 2026-03-27
Dovecot HIGH 7.5
CVE-2026-27858

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can for…

Fix: 2.3.22.1 / 2.4.3+
Fix from $1,950 2026-03-27
Dovecot HIGH 7.5
CVE-2026-27857

Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnec…

Fix: 2.3.22.1 / 2.4.3+
Fix from $1,950 2026-03-27
Incus MEDIUM 6.5
CVE-2026-33743

Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user wi…

Fix: 6.23.0+
Fix from $1,600 2026-03-26
Rails MEDIUM 6.5
CVE-2026-33658

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's p…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,600 2026-03-26
Pinchtab MEDIUM 6.5
CVE-2026-33621

PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` through `v0.8.4` contain incomplete…

Fix: 0.8.5+
Fix from $1,600 2026-03-26
Tsportal MEDIUM 6.5
CVE-2026-33541

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparenc…

Fix: 34+
Fix from $1,600 2026-03-26
Stirling Pdf MEDIUM 6.5
CVE-2026-33438

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions starting in 2.1.5 and prior to …

Fix: 2.5.2+
Fix from $1,600 2026-03-26
Openshift Container Platform MEDIUM 5.5
CVE-2026-4897

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set…

Mitigation only
Fix from $1,600 2026-03-26
Unclassified MEDIUM 6.5
CVE-2026-27663

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The …

Mitigation only
Fix from $1,600 2026-03-26
Nats Server MEDIUM 5.3
CVE-2026-33219

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious cli…

Fix: 2.11.15 / 2.12.6+
Fix from $1,600 2026-03-25