Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.5 CVE-2026-31826 pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can craft a PDF which leads to large… Pypdf 6.8.0+ Fix from $1,6002026-03-10 HIGH 7.5 CVE-2026-30946 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenti… Parse Server 8.6.15 / 9.5.2+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-26130 Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. Asp.net Core 8.0.25 / 9.0.14+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-30827 express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.… Express Rate Limit 8.0.2 / 8.2.2+ Fix from $1,9502026-03-07 HIGH 7.5 CVE-2026-29795 stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0.1, StringM::from_str does not… Stellar Xdr 25.0.1+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-26018 CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin tha… Coredns 1.14.2+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-29062 jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. From version 3.0.0 t… Jackson Core 3.1.0+ Fix from $1,9502026-03-06 HIGH 7.5 CVE-2026-29609 OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that allocates entire response payloads… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-29612 OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget limits, allowing attackers t… Openclaw 2026.2.14+ Fix from $1,9502026-03-05 HIGH 7.5 CVE-2026-28478 OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request bodies without strict byte or … Openclaw 2026.2.13+ Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2026-28452 OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src/infra/archive.ts that allows… Openclaw 2026.2.14+ Fix from $1,6002026-03-05 MEDIUM 6.5 CVE-2026-28394 OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attackers to crash the Gateway proce… Openclaw 2026.2.15+ Fix from $1,6002026-03-05 HIGH 7.5 CVE-2026-28342 OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthentic… Olivetin 3000.10.2+ Fix from $1,9502026-03-05 HIGH 8.6 CVE-2026-20103 A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Th… Adaptive Security Appliance Software 7.0.9 / 7.2.11+ Fix from $1,9502026-03-04 HIGH 7.5 CVE-2026-3520 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a D… Multer 2.1.1+ Fix from $1,9502026-03-04 HIGH 7.5 CVE-2026-27932 joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In 1.6.2 and earlier, a r… Joserfc after 1.6.2 Fix from $1,9502026-03-03 MEDIUM 5.9 CVE-2026-27601 Underscore.js is a utility-belt library for JavaScript. Prior to 1.13.8, the _.flatten and _.isEqual functions use recursion without a depth limit. U… Underscore 1.13.8+ Fix from $1,6002026-03-03 HIGH 7.5 CVE-2026-25673 An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit(… Django 4.2.29 / 5.2.12+ Fix from $1,9502026-03-03 MEDIUM 6.9 CVE-2026-27887 Spin is an open source developer tool for building and running serverless applications powered by WebAssembly. When Spin is configured to allow conne… Mitigation only Fix from $1,6002026-02-26 HIGH 7.5 CVE-2026-27633 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via me… Tinyweb 2.02+ Fix from $1,9502026-02-26 HIGH 7.5 CVE-2026-27630 TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack … Tinyweb 2.02+ Fix from $1,9502026-02-26 MEDIUM 6.5 CVE-2026-2845 An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could ha… GitLab 18.7.5 / 18.8.5+ Fix from $1,6002026-02-25 HIGH 7.5 CVE-2026-1662 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could … GitLab 18.7.5 / 18.8.5+ Fix from $1,9502026-02-25 HIGH 7.5 CVE-2026-1725 GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauth… GitLab Mitigation only Fix from $1,9502026-02-25 MEDIUM 6.5 CVE-2025-3525 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could h… GitLab 18.7.5 / 18.8.5+ Fix from $1,6002026-02-25 HIGH 7.5 CVE-2026-3201 USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service Wireshark 4.4.14 / 4.6.4+ Fix from $1,9502026-02-25 MEDIUM 5.3 CVE-2026-27695 zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets for a single entity share th… Zae Limiter 0.10.1+ Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2026-27204 Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interface… Wasmtime 24.0.6 / 36.0.6+ Fix from $1,6002026-02-24 HIGH 7.5 CVE-2026-27572 Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/type… Wasmtime 24.0.6 / 36.0.6+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-25899 Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `fiber_flash` cookie can force … Fiber 3.1.0+ Fix from $1,9502026-02-24