Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2026-25043 Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functional… Budibase 3.23.25+ Fix from $1,9502026-04-03 MEDIUM 5.5 CVE-2026-23468 In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Userspace … Linux Kernel 6.6.140 / 6.12.86+ Fix from $1,6002026-04-03 HIGH 7.5 CVE-2026-34827 Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mi… Rack 3.1.21 / 3.2.6+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-34593 Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 uncondit… Ash Framework 3.22.0+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-34829 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a Bo… Rack 2.2.23 / 3.1.21+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-34826 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header wi… Rack 2.2.23 / 3.1.21+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-31935 Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exh… Suricata 7.0.15 / 8.0.4+ Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-32145 Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing. Th… Wisp 2.2.2+ Fix from $1,9502026-04-02 MEDIUM 6.5 CVE-2026-5316 A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation… Stb Vorbis.c after 1.22 Fix from $1,6002026-04-02 MEDIUM 6.5 CVE-2025-66487 IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in e… Aspera Shares 1.11.1+ Fix from $1,6002026-04-01 HIGH 7.5 CVE-2026-34513 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in exces… Aiohttp 3.13.4+ Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-34516 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multi… Aiohttp 3.13.4+ Fix from $1,9502026-04-01 MEDIUM 5.3 CVE-2026-34517 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read… Aiohttp 3.13.4+ Fix from $1,6002026-04-01 HIGH 7.5 CVE-2026-22815 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer … Aiohttp 3.13.4+ Fix from $1,9502026-04-01 MEDIUM 5.0 CVE-2026-34165 go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identifi… Go Git 5.17.1+ Fix from $1,6002026-03-31 HIGH 7.5 CVE-2026-21710EPSS 26% A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application… Node.js after 25.8.1 Fix from $1,9502026-03-30 HIGH 7.5 CVE-2026-32980 OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing un… Openclaw 2026.3.13+ Fix from $1,9502026-03-29 HIGH 7.5 CVE-2026-33871 Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger … Netty 4.1.132 / 4.2.10+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-26061 Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies wi… Fleet 4.81.0+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-27880 The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes. Grafana 12.1.0 / 12.2.0+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-27858 Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can for… Dovecot 2.3.22.1 / 2.4.3+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-27857 Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnec… Dovecot 2.3.22.1 / 2.4.3+ Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2026-33743 Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user wi… Incus 6.23.0+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33658 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 Active Storage's p… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33621 PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` through `v0.8.4` contain incomplete… Pinchtab 0.8.5+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33541 TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparenc… Tsportal 34+ Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-33438 Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions starting in 2.1.5 and prior to … Stirling Pdf 2.5.2+ Fix from $1,6002026-03-26 MEDIUM 5.5 CVE-2026-4897 A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set… Openshift Container Platform Mitigation only Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-27663 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The … Mitigation only Fix from $1,6002026-03-26 MEDIUM 5.3 CVE-2026-33219 NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious cli… Nats Server 2.11.15 / 2.12.6+ Fix from $1,6002026-03-25