Vulnerability index

Browse CVEs

869 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Infinite LoopCWE-835 × clear
HIGH 7.5 CVE-2026-7263 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked li… PHP 8.4.21 / 8.5.6+ Fix from $1,9502026-05-10 MEDIUM 5.5 CVE-2026-42310 Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to ha… Pillow 12.2.0+ Fix from $1,6002026-05-09 MEDIUM 5.5 CVE-2026-41511 OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3,… Openmcdf 3.1.3+ Fix from $1,6002026-05-08 HIGH 7.5 CVE-2026-29975 lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end-of-string detection logic in… Mitigation only Fix from $1,9502026-05-08 HIGH 7.5 CVE-2026-33814 When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE… Go 0.53.0 / 1.25.10+ Fix from $1,9502026-05-07 MEDIUM 5.5 CVE-2026-43096 In the Linux kernel, the following vulnerability has been resolved: mshv: Fix infinite fault loop on permission-denied GPA intercepts Prevent infin… Linux Kernel 6.19.14+ Fix from $1,6002026-05-06 MEDIUM 5.5 CVE-2026-6528 TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30 MEDIUM 5.5 CVE-2026-6531 SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30 MEDIUM 5.5 CVE-2026-6534 USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30 MEDIUM 5.5 CVE-2026-6536 DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 Wireshark after 4.6.4 Fix from $1,6002026-04-30 HIGH 7.5 CVE-2026-6519 MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,9502026-04-30 HIGH 7.5 CVE-2026-6520 OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,9502026-04-30 MEDIUM 5.5 CVE-2026-6521 OpenFlow v5 protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30 MEDIUM 5.5 CVE-2026-6522 RPKI-Router protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30 MEDIUM 5.5 CVE-2026-6523 GNW protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30 MEDIUM 5.5 CVE-2026-5407 SMB2 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark after 4.6.4 Fix from $1,6002026-04-30 HIGH 7.5 CVE-2026-7375 UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service Wireshark 4.4.15 / 4.6.5+ Fix from $1,9502026-04-30 HIGH 7.5 CVE-2026-6985 A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of t… Mongoose 7.21+ Fix from $1,9502026-04-25 HIGH 7.5 CVE-2026-41680 Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a sp… Marked 18.0.2+ Fix from $1,9502026-04-24 MEDIUM 5.5 CVE-2026-31642 In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix call removal to use RCU safe deletion Fix rxrpc call removal from th… Linux Kernel 6.6.135 / 6.12.82+ Fix from $1,6002026-04-24 HIGH 7.5 CVE-2026-31552 In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom … Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-04-24 MEDIUM 5.5 CVE-2026-31498 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop l2cap_config_… Linux Kernel 4.5 / 4.10+ Fix from $1,6002026-04-22 MEDIUM 5.5 CVE-2026-31472 In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: validate inner IPv4 header length in IPTFS payload Add validation … Linux Kernel 6.18.21 / 6.19.11+ Fix from $1,6002026-04-22 CRITICAL 9.4 CVE-2026-31448 In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, whe… Linux Kernel 6.1.168 / 6.6.131+ Fix from $2,3002026-04-22 HIGH 8.7 CVE-2026-41146 facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinit… Patch available Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-34282 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Su… Jre Mitigation only Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-28214 Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize()… Firebird 3.0.14 / 4.0.7+ Fix from $1,6002026-04-17 HIGH 7.5 CVE-2026-33116 Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a … .net 8.0.26 / 9.0.15+ Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-34852 Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002026-04-13 MEDIUM 6.9 CVE-2026-39934 Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Lever… Mitigation only Fix from $1,6002026-04-07