Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Unclassified MEDIUM 5.9
CVE-2026-68762

In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible

Fix unknown
Fix from $4,000 2026-08-17
I HIGH 7.5
CVE-2026-17229

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.5
CVE-2026-17004

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop.

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-12236

The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-70462

rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disa…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-19484

@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-18726

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in t…

No fix yet
Fix from $4,000 2026-08-12
Security Verify Access HIGH 7.5
CVE-2026-11932

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 7.5
CVE-2026-16931

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options.

Fix: after 7.6
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-72712

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.7
CVE-2026-8798

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions …

No fix yet
Fix from $1,950 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-71436

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1,…

No fix yet
Fix from $1,600 2026-08-06
Hardened Images MEDIUM 5.1
CVE-2026-71227

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AI…

Fix: 1.5.1+
Fix from $1,600 2026-08-05
Zephyr HIGH 7.5
CVE-2026-10686

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet…

Fix: 4.5.0+
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.2
CVE-2026-68499

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global …

No fix yet
Fix from $1,600 2026-07-30
Netty HIGH 7.5
CVE-2026-59901

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-29
Nanoid HIGH 7.5
CVE-2026-67214

nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). Whe…

No fix yet
Fix from $1,950 2026-07-29
Nanoid HIGH 7.5
CVE-2026-67213

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a …

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.5
CVE-2026-59933

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-66730

facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker t…

No fix yet
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-43871

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thr…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Linux Kernel MEDIUM 5.5
CVE-2026-64290

In the Linux kernel, the following vulnerability has been resolved: iommufd: Break the loop on failure in iommufd_fault_fops_read() On a copy_to_us…

Fix: 6.12.101 / 6.18.39+
Fix from $1,600 2026-07-25
Unclassified HIGH 7.5
CVE-2026-64611

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-128…

No fix yet
Fix from $1,950 2026-07-23
Ffmpeg HIGH 7.5
CVE-2026-64834

FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote …

Fix: after 8.1.2
Fix from $1,950 2026-07-22
Unclassified MEDIUM 6.9
CVE-2026-16551

Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.6
CVE-2026-45820

fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry dec…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 7.5
CVE-2026-56852

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

No fix yet
Fix from $1,950 2026-07-21
Hardened Images HIGH 7.5
CVE-2026-59849

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when …

No fix yet
Fix from $1,950 2026-07-21
Hardened Images MEDIUM 6.5
CVE-2026-59843

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write…

No fix yet
Fix from $1,600 2026-07-21
Xrdp HIGH 7.5
CVE-2026-54538

xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLeng…

Fix: 0.10.6.1+
Fix from $1,950 2026-07-20