Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
GitLab MEDIUM 6.5
CVE-2025-13436

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that coul…

Fix: 18.8.7 / 18.9.3+
Fix from $1,600 2026-03-25
Bind HIGH 7.5
CVE-2026-1519

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-o…

Fix: 9.18.47 / 9.20.21+
Fix from $1,950 2026-03-25
Nicegui HIGH 7.5
CVE-2026-33332

NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-c…

Fix: 3.9.0+
Fix from $1,950 2026-03-24
\@astrojs\/node HIGH 7.5
CVE-2026-29772

Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enfor…

Fix: 10.0.0+
Fix from $1,950 2026-03-24
Salvo HIGH 7.5
CVE-2026-33241

Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do n…

Fix: 0.89.3+
Fix from $1,950 2026-03-24
Rails HIGH 7.5
CVE-2026-33176

Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and…

Fix: 7.2.3.1 / 8.0.4.1+
Fix from $1,950 2026-03-24
Avideo HIGH 7.5
CVE-2026-33483

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standa…

Fix: after 26.0
Fix from $1,950 2026-03-23
Openclaw HIGH 7.5
CVE-2026-32049

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple …

Fix: 2026.2.22+
Fix from $1,950 2026-03-21
Deepdiff HIGH 7.5
CVE-2026-33155

DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _Res…

Fix: 8.6.2+
Fix from $1,950 2026-03-20
Micronaut HIGH 7.5
CVE-2026-33012

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through…

Fix: 4.10.17+
Fix from $1,950 2026-03-20
Sliver MEDIUM 6.5
CVE-2026-32941

Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remote OOM (Out-of-Memory) vulner…

Fix: after 1.7.3
Fix from $1,600 2026-03-20
Openclaw HIGH 7.5
CVE-2026-32011

OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request …

Fix: 2026.3.2+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.5
CVE-2026-28461

OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that allows unauthenticated attacke…

Fix: 2026.3.1+
Fix from $1,950 2026-03-19
Dicebear HIGH 7.5
CVE-2026-29112

DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dicebear/converter` read the `wi…

Fix: 9.4.0+
Fix from $1,950 2026-03-18
Next.js HIGH 7.5
CVE-2026-27979

Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing t…

Fix: 16.1.7+
Fix from $1,950 2026-03-18
I HIGH 7.5
CVE-2026-1376

IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources.

Mitigation only
Fix from $1,950 2026-03-17
Mattermost Server HIGH 7.5
CVE-2026-24458

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to …

Fix: 10.11.11 / 11.2.3+
Fix from $1,950 2026-03-16
Wpdiscuz HIGH 7.5
CVE-2026-22182

wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by…

Fix: 7.6.47+
Fix from $1,950 2026-03-13
Undici MEDIUM 5.9
CVE-2026-2581

This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when i…

Fix: 7.24.0+
Fix from $1,600 2026-03-12
Undici HIGH 7.5
CVE-2026-1526

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. Whe…

Fix: 6.24.0 / 7.24.0+
Fix from $1,950 2026-03-12
Flatted HIGH 7.5
CVE-2026-32141

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deser…

Fix: 3.4.0+
Fix from $1,950 2026-03-12
Inspektor Gadget MEDIUM 5.5
CVE-2026-31890

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior t…

Fix: 0.50.1+
Fix from $1,600 2026-03-12
Quill MEDIUM 5.5
CVE-2026-31961

Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unbounded memory allocation vuln…

Fix: 0.7.1+
Fix from $1,600 2026-03-11
Quill MEDIUM 5.3
CVE-2026-31960

Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies …

Fix: 0.7.1+
Fix from $1,600 2026-03-11
Unclassified MEDIUM 5.5
CVE-2019-25464

InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash the application by entering an…

No fix yet
Fix from $1,600 2026-03-11
Flagd HIGH 7.5
CVE-2026-31866

flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and gRPC (evaluation.v1, evaluat…

Fix: 0.14.2+
Fix from $1,950 2026-03-11
GitLab HIGH 7.5
CVE-2025-13929

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could …

Fix: 18.7.6 / 18.8.6+
Fix from $1,950 2026-03-11
GitLab MEDIUM 6.5
CVE-2025-12576

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under c…

Fix: 18.7.6 / 18.8.6+
Fix from $1,600 2026-03-11
GitLab MEDIUM 6.5
CVE-2025-13690

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could…

Fix: 18.7.6 / 18.8.6+
Fix from $1,600 2026-03-11
Openclaw HIGH 7.5
CVE-2026-32062

OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 ac…

Fix: 2026.2.22+
Fix from $1,950 2026-03-11