Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Pypdf MEDIUM 5.5
CVE-2026-54531

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an i…

Fix: 6.13.0+
Fix from $1,600 2026-06-22
Pypdf MEDIUM 5.5
CVE-2026-54651

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an i…

Fix: 6.13.1+
Fix from $1,600 2026-06-22
Libssh2 HIGH 7.5
CVE-2026-55199

libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src…

Fix: after 1.11.1
Fix from $1,950 2026-06-17
Unclassified HIGH 7.5
CVE-2026-54417

An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontro…

Mitigation only
Fix from $1,950 2026-06-17
Imagemagick MEDIUM 5.5
CVE-2026-46521

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using L…

Fix: 6.9.13-48 / 7.1.2-23+
Fix from $1,600 2026-06-10
Imagemagick HIGH 7.5
CVE-2026-46522

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a mis…

Fix: 6.9.13-48 / 7.1.2-23+
Fix from $1,950 2026-06-10
Ghidra MEDIUM 5.5
CVE-2026-49495

Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks cycle detection when travers…

Fix: 12.1+
Fix from $1,600 2026-06-10
Image Size HIGH 7.5
CVE-2025-71329

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by suppl…

Fix: after 2.0.2
Fix from $1,950 2026-06-10
Image Size HIGH 7.5
CVE-2025-71330

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by suppl…

Fix: after 2.0.2
Fix from $1,950 2026-06-10
Discovery HIGH 7.5
CVE-2025-71319

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by suppl…

Fix: 1.4.2+
Fix from $1,950 2026-06-09
Linux Kernel MEDIUM 5.5
CVE-2026-46314

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Reject empty multisync extension to prevent infinite loop v3d_get_exte…

Fix: 6.1.176 / 6.18.33+
Fix from $1,600 2026-06-08
HTTP Server HIGH 7.3
CVE-2026-44186

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled ba…

Fix: 2.4.68+
Fix from $1,950 2026-06-08
Unclassified MEDIUM 6.5
CVE-2026-44740

Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or …

Mitigation only
Fix from $1,600 2026-06-01
Unclassified HIGH 7.5
CVE-2026-46385

iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value withou…

Mitigation only
Fix from $1,950 2026-05-29
Mermaid MEDIUM 5.3
CVE-2026-41150

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denia…

Fix: 10.9.6 / 11.15.0+
Fix from $1,600 2026-05-29
Linux Kernel MEDIUM 5.5
CVE-2026-46146

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() The convert…

Fix: 5.5 / 5.10.258+
Fix from $1,600 2026-05-28
Linux Kernel MEDIUM 5.5
CVE-2026-45919

In the Linux kernel, the following vulnerability has been resolved: sched/rt: Skip currently executing CPU in rto_next_cpu() CPU0 becomes overloade…

Fix: 4.5 / 4.10+
Fix from $1,600 2026-05-27
Linux Kernel MEDIUM 5.5
CVE-2026-45864

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent infinite loops caused by the next valid being the same When p…

Fix: 5.15.202 / 6.1.165+
Fix from $1,600 2026-05-27
Unclassified HIGH 7.1
CVE-2026-49017

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The S…

Mitigation only
Fix from $1,950 2026-05-27
Hackney HIGH 7.5
CVE-2026-47066

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header pars…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Libheif MEDIUM 6.5
CVE-2026-32739

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite lo…

Fix: 1.22.0+
Fix from $1,600 2026-05-19
Linux Kernel MEDIUM 5.5
CVE-2026-43486

In the Linux kernel, the following vulnerability has been resolved: arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS faults contpte_…

Fix: 6.12.78 / 6.18.19+
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-42920

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Managemen…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-42781

When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cause an increase in ePVA and Tr…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Bandit HIGH 7.5
CVE-2026-39806

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker pro…

Fix: 1.11.1+
Fix from $1,950 2026-05-13
Unclassified HIGH 7.5
CVE-2026-44302

Snappier is a high performance C# implementation of the Snappy compression algorithm. Prior to 1.3.1, Snappier.SnappyStream enters an uncatchable inf…

Mitigation only
Fix from $1,950 2026-05-12
.net HIGH 7.5
CVE-2026-42899

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.27 / 9.0.16+
Fix from $1,950 2026-05-12
Barebox MEDIUM 5.5
CVE-2026-34962

barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_ite…

Fix: 2026.04.0+
Fix from $1,600 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-8318

A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by this vulnerability is the func…

Mitigation only
Fix from $1,600 2026-05-11
Unclassified HIGH 7.5
CVE-2026-4890EPSS 7%

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS pa…

Patch available
Fix from $1,950 2026-05-11