VulnSea

CWE-1284

CVEs classified under CWE-1284, newest first.

74 CVEsRSS

CVE-2026-8813High· 7.5
4mo ago

This affects versions of the package exifreader before 4.39.0

This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the s…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-1101Medium· 6.5
5mo ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due …

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to cause denial of service to the GitLab instance due …

▾ Sunlitgitlab · gitlabEPSS 0.41%via NVD
CVE-2026-1092High· 7.5
5mo ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service due to improper input…

▾ Twilightgitlab · gitlabEPSS 0.55%via NVD
CVE-2025-12664High· 7.5
5mo ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated Gr…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an unauthenticated user to cause denial of service by sending repeated Gr…

▾ Twilightgitlab · gitlabEPSS 0.58%via NVD
CVE-2026-34756Medium· 6.5
5mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the…

▾ Sunlitvllm · vllmEPSS 0.77%via NVD
CVE-2026-3085High· 8.80day
6mo ago

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability

GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required…

▾ Abyssalgstreamer · gstreamerEPSS 1.2%via NVD
CVE-2026-2229High· 7.5
6mo ago

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automa…

▾ Twilightnodejs · undiciEPSS 0.87%via NVD
CVE-2026-1528High· 7.5
6mo ago

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the proces…

▾ Twilightnodejs · undiciEPSS 0.49%via NVD
CVE-2026-23864High· 7.5
8mo ago

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack. The vulnerabilities are triggered by sending s…

▾ Twilightfacebook · reactEPSS 2.6%via NVD
CVE-2023-7332None
9mo ago

PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling

PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in …

▾ SunlitEPSS 0.39%via NVD
CVE-2025-12385None
9mo ago

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. T…

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. T…

▾ SunlitEPSS 0.32%via NVD
CVE-2025-11568Medium· 4.4
11mo ago

A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format

A data corruption vulnerability has been identified in the luksmeta utility when used with the LUKS1 disk encryption format. An attacker with the necessary permissions can exploit this flaw by writing a large amount of metadata to an enc…

▾ SunlitEPSS 0.10%via NVD
CVE-2025-3511High· 7.5
1y ago

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link…

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link…

▾ TwilightEPSS 0.91%via NVD
CVE-2022-23635High· 7.5
4y ago

Istio is an open platform to connect, manage, and secure microservices

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted mes…

▾ Twilightistio · istioEPSS 1.7%via NVD
CWE-1284 vulnerabilities (CVEs) — page 3 · VulnSea