Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Linux Kernel HIGH 7.5
CVE-2026-64148

In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait Fix two cases where pdsc_devcm…

No fix yet
Fix from $1,950 2026-07-19
Surrealdb MEDIUM 6.5
CVE-2025-71397

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespac…

Fix: 2.0.5 / 2.1.5+
Fix from $1,600 2026-07-18
Unclassified MEDIUM 6.2
CVE-2026-45785

OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. In 3.1.3 and earlier, t…

No fix yet
Fix from $1,600 2026-07-17
Db2 MEDIUM 5.5
CVE-2026-7771

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries …

Fix: 12.1.5+
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.2
CVE-2026-46378

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer match…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.5
CVE-2026-13397

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-13401

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances …

No fix yet
Fix from $1,950 2026-07-16
Windows 10 1607 HIGH 7.5
CVE-2026-50647

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny servic…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 5.9
CVE-2026-50324

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny servic…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-54119

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
.net Framework HIGH 7.5
CVE-2026-50653

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

No fix yet
Fix from $1,950 2026-07-14
Webmail MEDIUM 6.5
CVE-2026-62642

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service u…

Fix: 1.6.17 / 1.7.2+
Fix from $1,600 2026-07-14
Pillow HIGH 7.5
CVE-2026-59203

Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%B…

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Unclassified HIGH 7.1
CVE-2026-55865

Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} …

Patch available
Fix from $1,950 2026-07-09
Patch MEDIUM 5.5
CVE-2026-56289

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-dif…

Fix: after 2.8.0
Fix from $1,600 2026-07-09
Unclassified HIGH 7.5
CVE-2026-54772

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote att…

Patch available
Fix from $1,950 2026-07-08
Wireshark HIGH 7.5
CVE-2026-15163

Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service

Fix: 4.4.17 / 4.6.7+
Fix from $1,950 2026-07-08
Pypdf HIGH 7.5
CVE-2026-59935

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not ter…

Fix: 6.14.2+
Fix from $1,950 2026-07-08
Immutable HIGH 7.5
CVE-2026-59879

Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the…

Fix: 4.3.9 / 5.1.8+
Fix from $1,950 2026-07-08
Protobufjs HIGH 7.5
CVE-2026-59877

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing throug…

Fix: 7.6.5 / 8.6.6+
Fix from $1,950 2026-07-08
Tar HIGH 7.5
CVE-2026-59874

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256…

Fix: 7.5.18+
Fix from $1,950 2026-07-08
Curl HIGH 7.5
CVE-2026-11352

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client.…

Fix: 8.21.0+
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.5
CVE-2026-14258

A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero…

Patch available
Fix from $1,600 2026-07-01
Linux Kernel MEDIUM 5.5
CVE-2026-53312

In the Linux kernel, the following vulnerability has been resolved: iommu/riscv: Remove overflows on the invalidation path Since RISC-V supports a …

Fix: 6.18.33 / 7.0.10+
Fix from $1,600 2026-06-26
Zephyr MEDIUM 6.5
CVE-2026-10642

The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the i…

Fix: 4.5.0+
Fix from $1,600 2026-06-24
Concurrent Ruby HIGH 7.5
CVE-2026-54904

concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when…

Fix: 1.3.7+
Fix from $1,950 2026-06-24
Linux Kernel MEDIUM 5.5
CVE-2026-52965

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure When ttm_tt_…

Fix: 7.0.10+
Fix from $1,600 2026-06-24
Linux Kernel HIGH 7.8
CVE-2026-52933

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_own…

Fix: 5.16 / 6.1+
Fix from $1,950 2026-06-24
Linux Kernel MEDIUM 5.5
CVE-2026-52921

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: stop hash:* range iteration at end The following hash set var…

Fix: 5.10.258 / 5.15.209+
Fix from $1,600 2026-06-24
Pypdf MEDIUM 5.5
CVE-2026-54530

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an i…

Fix: 6.13.0+
Fix from $1,600 2026-06-22