Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
Aardvark Dns HIGH 7.5
CVE-2026-35406

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection r…

Fix: 1.17.1+
Fix from $1,950 2026-04-07
Linux Kernel MEDIUM 5.5
CVE-2026-23472

In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN uart_write_room…

Fix: 6.18.20 / 6.19.10+
Fix from $1,600 2026-04-03
Linux Kernel HIGH 7.5
CVE-2026-23451

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_par…

Patch available
Fix from $1,950 2026-04-03
Linux Kernel MEDIUM 5.5
CVE-2026-23409

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix differential encoding verification Differential encoding allows l…

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-04-01
Forge HIGH 7.5
CVE-2026-33891

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (D…

Fix: after 1.3.3
Fix from $1,950 2026-03-27
Pypdf HIGH 7.5
CVE-2026-33699

pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which lead…

Fix: 6.9.2+
Fix from $1,950 2026-03-27
Xpath HIGH 7.5
CVE-2026-32287

Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered b…

Fix: 1.3.6+
Fix from $1,950 2026-03-26
Linux Kernel MEDIUM 5.5
CVE-2026-23298

In the Linux kernel, the following vulnerability has been resolved: can: ucan: Fix infinite loop from zero-length messages If a broken ucan device …

Fix: 5.10.253 / 5.15.203+
Fix from $1,600 2026-03-25
Jsrsasign HIGH 7.5
CVE-2026-4598

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.mod…

Fix: 11.1.1+
Fix from $1,950 2026-03-23
Micronaut HIGH 7.5
CVE-2026-33013

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both …

Fix: 3.10.5 / 4.10.16+
Fix from $1,950 2026-03-20
Tinytag MEDIUM 6.5
CVE-2026-32889

tinytag is a Python library for reading audio file metadata. Version 2.2.0 allows an attacker who can supply MP3 files for parsing to trigger a non-t…

Patch available
Fix from $1,600 2026-03-20
Ewe HIGH 7.5
CVE-2026-32873

ewe is a Gleam web server. Versions 0.8.0 through 3.0.4 contain a bug in the handle_trailers function where rejected trailer headers (forbidden or un…

Fix: 3.0.5+
Fix from $1,950 2026-03-20
Ultrajson HIGH 7.5
CVE-2026-32875

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer o…

Fix: 5.12.0+
Fix from $1,950 2026-03-20
Linux Kernel MEDIUM 5.5
CVE-2025-71265

In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata W…

Fix: 5.15.202 / 6.1.165+
Fix from $1,600 2026-03-18
Linux Kernel MEDIUM 5.5
CVE-2025-71266

In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: check return value of indx_find to avoid infinite loop We found an i…

Fix: 5.15.202 / 6.1.165+
Fix from $1,600 2026-03-18
Linux Kernel MEDIUM 5.5
CVE-2025-71267

In the Linux kernel, the following vulnerability has been resolved: fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST We found an infi…

Fix: 5.15.202 / 6.1.165+
Fix from $1,600 2026-03-18
Music Metadata HIGH 7.5
CVE-2026-32256

music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF parser (`parseExtensionObject()` …

Fix: 11.12.3+
Fix from $1,950 2026-03-18
Pyasn1 HIGH 7.5
CVE-2026-30922

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncont…

Fix: 0.6.3+
Fix from $1,950 2026-03-18
Zephyr MEDIUM 6.1
CVE-2026-4179

Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.

Fix: after 4.3.0
Fix from $1,600 2026-03-16
Libexpat MEDIUM 5.5
CVE-2026-32777

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

Fix: 2.7.5+
Fix from $1,600 2026-03-16
Unclassified HIGH 7.5
CVE-2026-4111

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path.…

Patch available
Fix from $1,950 2026-03-13
File Type MEDIUM 5.3
CVE-2026-31808

file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in the ASF (WMV/WMA) file type …

Fix: 21.3.1+
Fix from $1,600 2026-03-10
Binutils MEDIUM 6.2
CVE-2025-69648

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists dat…

Fix: after 2.45.1
Fix from $1,600 2026-03-09
Binutils MEDIUM 6.2
CVE-2025-69647

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A lo…

Fix: after 2.45.1
Fix from $1,600 2026-03-09
Dpkg HIGH 7.5
CVE-2026-2219

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream whe…

Fix: 1.21.23 / 1.22.22+
Fix from $1,950 2026-03-07
Unclassified MEDIUM 5.8
CVE-2026-20054

Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the …

Mitigation only
Fix from $1,600 2026-03-04
Pypdf HIGH 7.5
CVE-2026-27628

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an in…

Fix: 6.7.2+
Fix from $1,950 2026-02-25
Imagemagick HIGH 7.5
CVE-2026-26283

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a `continue`…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-02-24
Imagemagick HIGH 7.5
CVE-2026-26066

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted pr…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-02-24
Pypdf MEDIUM 5.5
CVE-2026-27024

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an in…

Fix: 6.7.1+
Fix from $1,600 2026-02-20