Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
PHP HIGH 7.5
CVE-2026-7263

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked li…

Fix: 8.4.21 / 8.5.6+
Fix from $1,950 2026-05-10
Pillow MEDIUM 5.5
CVE-2026-42310

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to ha…

Fix: 12.2.0+
Fix from $1,600 2026-05-09
Openmcdf MEDIUM 5.5
CVE-2026-41511

OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3,…

Fix: 3.1.3+
Fix from $1,600 2026-05-08
Unclassified HIGH 7.5
CVE-2026-29975

lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic in…

Mitigation only
Fix from $1,950 2026-05-08
Go HIGH 7.5
CVE-2026-33814

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE…

Fix: 0.53.0 / 1.25.10+
Fix from $1,950 2026-05-07
Linux Kernel MEDIUM 5.5
CVE-2026-43096

In the Linux kernel, the following vulnerability has been resolved: mshv: Fix infinite fault loop on permission-denied GPA intercepts Prevent infin…

Fix: 6.19.14+
Fix from $1,600 2026-05-06
Wireshark MEDIUM 5.5
CVE-2026-6528

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6531

SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6534

USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6536

DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark HIGH 7.5
CVE-2026-6519

MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,950 2026-04-30
Wireshark HIGH 7.5
CVE-2026-6520

OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,950 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6521

OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6522

RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-6523

GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark MEDIUM 5.5
CVE-2026-5407

SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: after 4.6.4
Fix from $1,600 2026-04-30
Wireshark HIGH 7.5
CVE-2026-7375

UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Fix: 4.4.15 / 4.6.5+
Fix from $1,950 2026-04-30
Mongoose HIGH 7.5
CVE-2026-6985

A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of t…

Fix: 7.21+
Fix from $1,950 2026-04-25
Marked HIGH 7.5
CVE-2026-41680

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a sp…

Fix: 18.0.2+
Fix from $1,950 2026-04-24
Linux Kernel MEDIUM 5.5
CVE-2026-31642

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix call removal to use RCU safe deletion Fix rxrpc call removal from th…

Fix: 6.6.135 / 6.12.82+
Fix from $1,600 2026-04-24
Linux Kernel HIGH 7.5
CVE-2026-31552

In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom …

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-24
Linux Kernel MEDIUM 5.5
CVE-2026-31498

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop l2cap_config_…

Fix: 4.5 / 4.10+
Fix from $1,600 2026-04-22
Linux Kernel MEDIUM 5.5
CVE-2026-31472

In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: validate inner IPv4 header length in IPTFS payload Add validation …

Fix: 6.18.21 / 6.19.11+
Fix from $1,600 2026-04-22
Linux Kernel CRITICAL 9.4
CVE-2026-31448

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, whe…

Fix: 6.1.168 / 6.6.131+
Fix from $2,300 2026-04-22
Unclassified HIGH 8.7
CVE-2026-41146

facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinit…

Patch available
Fix from $1,950 2026-04-22
Jre HIGH 7.5
CVE-2026-34282

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Su…

Mitigation only
Fix from $1,950 2026-04-21
Firebird MEDIUM 6.5
CVE-2026-28214

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize()…

Fix: 3.0.14 / 4.0.7+
Fix from $1,600 2026-04-17
.net HIGH 7.5
CVE-2026-33116

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a …

Fix: 8.0.26 / 9.0.15+
Fix from $1,950 2026-04-14
Harmonyos MEDIUM 6.5
CVE-2026-34852

Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-04-13
Unclassified MEDIUM 6.9
CVE-2026-39934

Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Lever…

Mitigation only
Fix from $1,600 2026-04-07