Vulnerability index

Browse CVEs

130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-6985 A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of t… Mongoose 7.21+ Fix from $1,9502026-04-25 HIGH 8.1 CVE-2026-5245 A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS R… Mongoose 7.21+ Fix from $1,9502026-04-02 HIGH 8.1 CVE-2026-5246 A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the co… Mongoose 7.21+ Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-5244 A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS… Mongoose 7.21+ Fix from $2,3002026-04-02 HIGH 7.5 CVE-2025-51495 An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an a… Mongoose after 7.17 Fix from $1,9502025-09-29 HIGH 7.5 CVE-2024-42392 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string c… Mongoose after 7.14 Fix from $1,9502024-11-18 MEDIUM 5.3 CVE-2024-42389 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force t… Mongoose after 7.14 Fix from $1,6002024-11-18 MEDIUM 5.3 CVE-2024-42390 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force t… Mongoose after 7.14 Fix from $1,6002024-11-18 MEDIUM 5.3 CVE-2024-42391 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force t… Mongoose after 7.14 Fix from $1,6002024-11-18 HIGH 7.5 CVE-2024-42386 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce… Mongoose after 7.14 Fix from $1,9502024-11-18 HIGH 7.0 CVE-2024-42385 Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM ce… Mongoose after 7.14 Fix from $1,9502024-11-18 MEDIUM 5.3 CVE-2024-42387 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force t… Mongoose after 7.14 Fix from $1,6002024-11-18 MEDIUM 5.3 CVE-2024-42388 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force t… Mongoose after 7.14 Fix from $1,6002024-11-18 CRITICAL 9.8 CVE-2024-42383 Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedic… Mongoose after 7.14 Fix from $2,3002024-11-18 HIGH 7.5 CVE-2024-42384 Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a s… Mongoose after 7.14 Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-35386 An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the mjs.c file. Mjs No fix yet Fix from $1,9502024-05-21 MEDIUM 5.5 CVE-2024-35384 An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function in the mjs.c file. Mjs No fix yet Fix from $1,6002024-05-21 HIGH 7.5 CVE-2023-49549 An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file. Mjs No fix yet Fix from $1,9502024-01-02 HIGH 7.5 CVE-2023-49550 An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component. Mjs No fix yet Fix from $1,9502024-01-02 HIGH 7.5 CVE-2023-49551 An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file. Mjs No fix yet Fix from $1,9502024-01-02 HIGH 7.5 CVE-2023-49552 An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.… Mjs No fix yet Fix from $1,9502024-01-02 HIGH 7.5 CVE-2023-49553 An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file. Mjs No fix yet Fix from $1,9502024-01-02 CRITICAL 9.8 CVE-2023-50044 Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string. Mjs Patch available Fix from $2,3002023-12-20 CRITICAL 9.8 CVE-2023-43338 Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows at… Mjs No fix yet Fix from $2,3002023-09-23 HIGH 8.8 CVE-2020-25887 Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file. Mongoose No fix yet Fix from $1,9502023-08-22 HIGH 8.8 CVE-2023-2905 Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddabl… Mongoose Patch available Fix from $1,9502023-08-09 HIGH 7.5 CVE-2023-34188 The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an … Mongoose 7.10+ Fix from $1,9502023-06-23 MEDIUM 5.5 CVE-2023-30087 Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in mjs.… Mjs No fix yet Fix from $1,6002023-05-09 MEDIUM 5.5 CVE-2023-30088 An issue found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_execute function in mjs.c. Mjs No fix yet Fix from $1,6002023-05-09 MEDIUM 5.5 CVE-2023-29570 Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a Denial of S… Mjs No fix yet Fix from $1,6002023-04-24