VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

622 CVEsRSS

CVE-2025-61478High· 7.5
1mo ago

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.

▾ TwilightEPSS 0.26%via NVD
CVE-2026-51106Critical· 9.3
1mo ago

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component

An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component

▾ MidnightEPSS 0.40%via NVD
CVE-2026-19401High· 7.5
1mo ago

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512)

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the …

▾ Twilightnlnetlabs · nsdEPSS 0.28%via NVD
CVE-2026-78684Medium· 5.3
1mo ago

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode p…

▾ SunlitEPSS 0.57%via NVD
CVE-2026-15310Low· 2.1
1mo ago

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

▾ SunlitPython Software Foundation · CPythonEPSS 0.50%via NVD
CVE-2026-77357None
1mo ago

Mesop is a Python-based UI framework that allows users to build web applications

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, applications running in debug mode expose a GET /hot-reload endpoint whose unbounded loop depends on the user-supplied counter parameter, a…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-55373Medium· 6.2
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. Th…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-71360High· 7.5
1mo ago

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an applica…

▾ Twilightadobe · c2paEPSS 0.90%via NVD
CVE-2026-79658High· 7.5
1mo ago

Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request

Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request. The header is passed unfiltered to go-i18n's NewLocalizer, which internally calls…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-55588Medium· 6.5⚖ disputed
1mo ago

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registr…

▾ Sunlitoras · oras.land/orasEPSS 0.54%via NVD
CVE-2026-55099High· 7.5
1mo ago

icalendar has Algorithmic Complexity in Equality

icalendar has Algorithmic Complexity in Equality

▾ Twilighticalendar · icalendarEPSS 0.63%via OSV
CVE-2026-54338Medium· 5.3
1mo ago

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

▾ Sunlitjupyterhub · jupyterhubEPSS 0.44%via OSV
CVE-2026-55531Medium· 6.5
1mo ago

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

▾ Sunlitpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-53965High
1mo ago

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to …

▾ Twilightmcp · mcp/sdkEPSS 0.61%via NVD
CVE-2026-77384High· 7.5
1mo ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on e…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-75371High· 7.5
1mo ago

An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.

An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-55241High· 7.5
1mo ago

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in…

▾ TwilightEPSS 0.62%via NVD
CVE-2026-77354High· 7.5
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter into a…

▾ Twilightgetkin · github.com/getkin/kin-openapiEPSS 0.52%via NVD
CVE-2026-53530High
1mo ago

RaTeX is a KaTeX-compatible math rendering engine written in Rust

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` panics on the 9-byte input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter …

▾ Twilightratex-parser · ratex-parserEPSS 0.43%via NVD
CVE-2026-53531Medium
1mo ago

RaTeX is a KaTeX-compatible math rendering engine written in Rust

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with no maximu…

▾ Sunlitratex-parser · ratex-parserEPSS 0.43%via NVD
CVE-2026-48050High· 8.2
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `…

▾ TwilightRed Hat · Red Hat Edge Manager 1EPSS 0.64%via NVD
CVE-2026-63495High· 7.5PoC
1mo ago

Libevent is an event notification library

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenti…

▾ Midnightlibevent · libeventEPSS 0.61%via NVD
CVE-2026-67446Medium· 5.3⚖ disputed
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded dimensions, pixel count, or memory use in the GET /api/v1/message/{i…

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.51%via NVD
CVE-2026-67445Medium· 5.3⚖ disputed
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLine() using bufio.Reader.ReadString before session.parseLine() parses the verb or the RFC …

▾ Sunlitaxllent · github.com/axllent/mailpitEPSS 0.51%via NVD
GHSA-22w5-2fxg-vrwxLow· 2.6
1mo ago

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or c…

OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers

▾ Sunlitopentofu · github.com/opentofu/opentofuvia OSV
CVE-2026-54260Medium· 4.3
1mo ago

Wagtail: Denial of service via unbounded filter specs in the image preview

Wagtail: Denial of service via unbounded filter specs in the image preview

▾ Sunlitwagtail · wagtailEPSS 0.37%via GHSA
CVE-2026-63124High· 7.5
1mo ago

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary

▾ Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-61827High
1mo ago

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields

▾ Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-63202High· 7.5
1mo ago

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

▾ Twilightnetty · io.netty.incubator:netty-incubator-codec-bhttpvia GHSA
CVE-2026-68555Medium· 6.5
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh UDP 5-tuples without completing a handoff when the server enables --mobility. mobi…

▾ SunlitEPSS 0.53%via NVD
CWE-400 vulnerabilities (CVEs) — page 10 · VulnSea