Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
HIGH 7.5 CVE-2026-64148 In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait Fix two cases where pdsc_devcm… Linux Kernel No fix yet Fix from $1,9502026-07-19 MEDIUM 6.5 CVE-2025-71397 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespac… Surrealdb 2.0.5 / 2.1.5+ Fix from $1,6002026-07-18 MEDIUM 6.2 CVE-2026-45785 OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. In 3.1.3 and earlier, t… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.5 CVE-2026-7771 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries … Db2 12.1.5+ Fix from $1,6002026-07-17 MEDIUM 6.2 CVE-2026-46378 Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer match… No fix yet Fix from $1,6002026-07-16 HIGH 7.5 CVE-2026-13397 HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances… No fix yet Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-13401 XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances … No fix yet Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-50647 Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny servic… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 5.9 CVE-2026-50324 Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny servic… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-54119 Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-50653 Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. .net Framework No fix yet Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-62642 In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service u… Webmail 1.6.17 / 1.7.2+ Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-59203 Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%B… Pillow 12.3.0+ Fix from $1,9502026-07-14 HIGH 7.1 CVE-2026-55865 Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} … Patch available Fix from $1,9502026-07-09 MEDIUM 5.5 CVE-2026-56289 GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-dif… Patch after 2.8.0 Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-54772 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote att… Patch available Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-15163 Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service Wireshark 4.4.17 / 4.6.7+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59935 pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a not ter… Pypdf 6.14.2+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59879 Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the… Immutable 4.3.9 / 5.1.8+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59877 protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed option names by advancing throug… Protobufjs 7.6.5 / 8.6.6+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59874 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256… Tar 7.5.18+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-11352 An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client.… Curl 8.21.0+ Fix from $1,9502026-07-03 MEDIUM 6.5 CVE-2026-14258 A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero… Patch available Fix from $1,6002026-07-01 MEDIUM 5.5 CVE-2026-53312 In the Linux kernel, the following vulnerability has been resolved: iommu/riscv: Remove overflows on the invalidation path Since RISC-V supports a … Linux Kernel 6.18.33 / 7.0.10+ Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-10642 The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the i… Zephyr 4.5.0+ Fix from $1,6002026-06-24 HIGH 7.5 CVE-2026-54904 concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when… Concurrent Ruby 1.3.7+ Fix from $1,9502026-06-24 MEDIUM 5.5 CVE-2026-52965 In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure When ttm_tt_… Linux Kernel 7.0.10+ Fix from $1,6002026-06-24 HIGH 7.8 CVE-2026-52933 In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get_ownership() io_poll_get_own… Linux Kernel 5.16 / 6.1+ Fix from $1,9502026-06-24 MEDIUM 5.5 CVE-2026-52921 In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: stop hash:* range iteration at end The following hash set var… Linux Kernel 5.10.258 / 5.15.209+ Fix from $1,6002026-06-24 MEDIUM 5.5 CVE-2026-54530 pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an i… Pypdf 6.13.0+ Fix from $1,6002026-06-22