Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 6.5 CVE-2025-13436 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that coul… GitLab 18.8.7 / 18.9.3+ Fix from $1,6002026-03-25 HIGH 7.5 CVE-2026-1519 If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-o… Bind 9.18.47 / 9.20.21+ Fix from $1,9502026-03-25 HIGH 7.5 CVE-2026-33332 NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files() media routes accept a user-c… Nicegui 3.9.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-29772 Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enfor… \@astrojs\/node 10.0.0+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33241 Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do n… Salvo 0.89.3+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33176 Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and… Rails 7.2.3.1 / 8.0.4.1+ Fix from $1,9502026-03-24 HIGH 7.5 CVE-2026-33483 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standa… Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 7.5 CVE-2026-32049 OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple … Openclaw 2026.2.22+ Fix from $1,9502026-03-21 HIGH 7.5 CVE-2026-33155 DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6.2, the pickle unpickler _Res… Deepdiff 8.6.2+ Fix from $1,9502026-03-20 HIGH 7.5 CVE-2026-33012 Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions 4.7.0 through… Micronaut 4.10.17+ Fix from $1,9502026-03-20 MEDIUM 6.5 CVE-2026-32941 Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remote OOM (Out-of-Memory) vulner… Sliver after 1.7.3 Fix from $1,6002026-03-20 HIGH 7.5 CVE-2026-32011 OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request … Openclaw 2026.3.2+ Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-28461 OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that allows unauthenticated attacke… Openclaw 2026.3.1+ Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-29112 DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dicebear/converter` read the `wi… Dicebear 9.4.0+ Fix from $1,9502026-03-18 HIGH 7.5 CVE-2026-27979 Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing t… Next.js 16.1.7+ Fix from $1,9502026-03-18 HIGH 7.5 CVE-2026-1376 IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to improper allocation of resources. I Mitigation only Fix from $1,9502026-03-17 HIGH 7.5 CVE-2026-24458 Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to … Mattermost Server 10.11.11 / 11.2.3+ Fix from $1,9502026-03-16 HIGH 7.5 CVE-2026-22182 wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by… Wpdiscuz 7.6.47+ Fix from $1,9502026-03-13 MEDIUM 5.9 CVE-2026-2581 This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when i… Undici 7.24.0+ Fix from $1,6002026-03-12 HIGH 7.5 CVE-2026-1526 The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. Whe… Undici 6.24.0 / 7.24.0+ Fix from $1,9502026-03-12 HIGH 7.5 CVE-2026-32141 flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deser… Flatted 3.4.0+ Fix from $1,9502026-03-12 MEDIUM 5.5 CVE-2026-31890 Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior t… Inspektor Gadget 0.50.1+ Fix from $1,6002026-03-12 MEDIUM 5.5 CVE-2026-31961 Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unbounded memory allocation vuln… Quill 0.7.1+ Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2026-31960 Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded reads of HTTP response bodies … Quill 0.7.1+ Fix from $1,6002026-03-11 MEDIUM 5.5 CVE-2019-25464 InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash the application by entering an… No fix yet Fix from $1,6002026-03-11 HIGH 7.5 CVE-2026-31866 flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and gRPC (evaluation.v1, evaluat… Flagd 0.14.2+ Fix from $1,9502026-03-11 HIGH 7.5 CVE-2025-13929 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could … GitLab 18.7.6 / 18.8.6+ Fix from $1,9502026-03-11 MEDIUM 6.5 CVE-2025-12576 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under c… GitLab 18.7.6 / 18.8.6+ Fix from $1,6002026-03-11 MEDIUM 6.5 CVE-2025-13690 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could… GitLab 18.7.6 / 18.8.6+ Fix from $1,6002026-03-11 HIGH 7.5 CVE-2026-32062 OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, but not including, 2026.2.22 ac… Openclaw 2026.2.22+ Fix from $1,9502026-03-11