Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.1 CVE-2026-39959 Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to malicious D-Bus peers. A peer … Mitigation only Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-5440 A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directl… Orthanc 1.12.11+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-5438 A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits … Orthanc 1.12.11+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-5439 A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and tru… Orthanc 1.12.11+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-24661 Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker… Mattermost 2.3.2.0+ Fix from $1,6002026-04-09 MEDIUM 6.5 CVE-2026-21388 Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker… Mattermost Server after 2.3.1 Fix from $1,6002026-04-09 HIGH 7.5 CVE-2026-40036 Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of s… Unfurl 2026.04+ Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-39414 MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO's S3 Select featur… Minio after 2025-10-15t17-29-55z Fix from $1,6002026-04-08 HIGH 7.5 CVE-2026-23869 A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turb… Mitigation only Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-35401 Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations… Saleor 3.20.118 / 3.21.54+ Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-33756 Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multipl… Saleor 3.20.118 / 3.21.54+ Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-32280 During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in Verify… Go 1.25.9 / 1.26.2+ Fix from $1,9502026-04-08 HIGH 7.5 CVE-2026-32283 If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontro… Go 1.25.9 / 1.26.2+ Fix from $1,9502026-04-08 MEDIUM 5.5 CVE-2026-32288 tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded … Go 1.25.9 / 1.26.2+ Fix from $1,6002026-04-08 CRITICAL 9.1 CVE-2026-34045 Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des… Podman Desktop 1.26.2+ Fix from $2,3002026-04-07 HIGH 7.5 CVE-2026-29181 OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-va… Opentelemetry 1.41.0+ Fix from $1,9502026-04-07 MEDIUM 5.3 CVE-2026-5762 Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS. This… Mitigation only Fix from $1,6002026-04-07 HIGH 7.5 CVE-2026-35526 Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphq… Strawberry Graphql 0.312.3+ Fix from $1,9502026-04-07 MEDIUM 6.2 CVE-2026-35480 go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C… Go Ipld Prime 0.22.0+ Fix from $1,6002026-04-07 HIGH 7.5 CVE-2026-35405 libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on ho… Libp2p 0.17.1+ Fix from $1,9502026-04-07 HIGH 8.2 CVE-2026-35457 libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination coo… Libp2p 0.17.1+ Fix from $1,9502026-04-07 HIGH 7.5 CVE-2026-33034 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` h… Django 4.2.30 / 5.2.13+ Fix from $1,9502026-04-07 MEDIUM 6.5 CVE-2026-20431 In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base s… Mt6813 Firmware Mitigation only Fix from $1,6002026-04-07 MEDIUM 6.5 CVE-2026-35441 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql… Directus 11.17.0+ Fix from $1,6002026-04-06 MEDIUM 6.5 CVE-2026-34755 vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/… Vllm 0.19.0+ Fix from $1,6002026-04-06 MEDIUM 6.5 CVE-2026-34756 vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in th… Vllm 0.19.0+ Fix from $1,6002026-04-06 HIGH 7.5 CVE-2026-34148 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify fo… Fedify\/fedify 1.9.6 / 1.10.5+ Fix from $1,9502026-04-06 HIGH 7.5 CVE-2026-34824 Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resourc… Mesop 1.2.5+ Fix from $1,9502026-04-03 MEDIUM 5.9 CVE-2026-34052 LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-leve… Lti Jupyterhub Authenticator 1.6.3+ Fix from $1,6002026-04-03 HIGH 7.5 CVE-2026-35562 Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a de… Athena Odbc 2.1.0.0+ Fix from $1,9502026-04-03