Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Pypdf MEDIUM 5.5
CVE-2026-31826

pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can craft a PDF which leads to large…

Fix: 6.8.0+
Fix from $1,600 2026-03-10
Parse Server HIGH 7.5
CVE-2026-30946

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenti…

Fix: 8.6.15 / 9.5.2+
Fix from $1,950 2026-03-10
Asp.net Core HIGH 7.5
CVE-2026-26130

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.25 / 9.0.14+
Fix from $1,950 2026-03-10
Express Rate Limit HIGH 7.5
CVE-2026-30827

express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.…

Fix: 8.0.2 / 8.2.2+
Fix from $1,950 2026-03-07
Stellar Xdr HIGH 7.5
CVE-2026-29795

stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0.1, StringM::from_str does not…

Fix: 25.0.1+
Fix from $1,950 2026-03-06
Coredns HIGH 7.5
CVE-2026-26018

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin tha…

Fix: 1.14.2+
Fix from $1,950 2026-03-06
Jackson Core HIGH 7.5
CVE-2026-29062

jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 t…

Fix: 3.1.0+
Fix from $1,950 2026-03-06
Openclaw HIGH 7.5
CVE-2026-29609

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that allocates entire response payloads…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.5
CVE-2026-29612

OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers t…

Fix: 2026.2.14+
Fix from $1,950 2026-03-05
Openclaw HIGH 7.5
CVE-2026-28478

OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or …

Fix: 2026.2.13+
Fix from $1,950 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-28452

OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows…

Fix: 2026.2.14+
Fix from $1,600 2026-03-05
Openclaw MEDIUM 6.5
CVE-2026-28394

OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway proce…

Fix: 2026.2.15+
Fix from $1,600 2026-03-05
Olivetin HIGH 7.5
CVE-2026-28342

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthentic…

Fix: 3000.10.2+
Fix from $1,950 2026-03-05
Adaptive Security Appliance Software HIGH 8.6
CVE-2026-20103

A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Th…

Fix: 7.0.9 / 7.2.11+
Fix from $1,950 2026-03-04
Multer HIGH 7.5
CVE-2026-3520

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a D…

Fix: 2.1.1+
Fix from $1,950 2026-03-04
Joserfc HIGH 7.5
CVE-2026-27932

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a r…

Fix: after 1.6.2
Fix from $1,950 2026-03-03
Underscore MEDIUM 5.9
CVE-2026-27601

Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. U…

Fix: 1.13.8+
Fix from $1,600 2026-03-03
Django HIGH 7.5
CVE-2026-25673

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit(…

Fix: 4.2.29 / 5.2.12+
Fix from $1,950 2026-03-03
Unclassified MEDIUM 6.9
CVE-2026-27887

Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow conne…

Mitigation only
Fix from $1,600 2026-02-26
Tinyweb HIGH 7.5
CVE-2026-27633

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via me…

Fix: 2.02+
Fix from $1,950 2026-02-26
Tinyweb HIGH 7.5
CVE-2026-27630

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack …

Fix: 2.02+
Fix from $1,950 2026-02-26
GitLab MEDIUM 6.5
CVE-2026-2845

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could ha…

Fix: 18.7.5 / 18.8.5+
Fix from $1,600 2026-02-25
GitLab HIGH 7.5
CVE-2026-1662

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could …

Fix: 18.7.5 / 18.8.5+
Fix from $1,950 2026-02-25
GitLab HIGH 7.5
CVE-2026-1725

GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauth…

Mitigation only
Fix from $1,950 2026-02-25
GitLab MEDIUM 6.5
CVE-2025-3525

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could h…

Fix: 18.7.5 / 18.8.5+
Fix from $1,600 2026-02-25
Wireshark HIGH 7.5
CVE-2026-3201

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

Fix: 4.4.14 / 4.6.4+
Fix from $1,950 2026-02-25
Zae Limiter MEDIUM 5.3
CVE-2026-27695

zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets for a single entity share th…

Fix: 0.10.1+
Fix from $1,600 2026-02-25
Wasmtime MEDIUM 6.5
CVE-2026-27204

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interface…

Fix: 24.0.6 / 36.0.6+
Fix from $1,600 2026-02-24
Wasmtime HIGH 7.5
CVE-2026-27572

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/type…

Fix: 24.0.6 / 36.0.6+
Fix from $1,950 2026-02-24
Fiber HIGH 7.5
CVE-2026-25899

Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force …

Fix: 3.1.0+
Fix from $1,950 2026-02-24