Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26897
Total
1982
Critical
8080
High
8318
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-33376 | HIGH | 7.4 | When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate … | May 13, 2026 |
| CVE-2026-28383 | MEDIUM | 6.5 | A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can … | May 13, 2026 |
| CVE-2026-28380 | MEDIUM | 6.5 | Any Editor could delete any snapshot, even if they have no access to read or write them. | May 13, 2026 |
| CVE-2026-28379 | MEDIUM | 6.5 | A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal … | May 13, 2026 |
| CVE-2026-28376 | MEDIUM | 6.5 | The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory … | May 13, 2026 |
| CVE-2026-28374 | MEDIUM | 4.3 | Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations. | May 13, 2026 |
| CVE-2026-0243 | UNKNOWN | — | A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma … | May 13, 2026 |
| CVE-2026-8496 | MEDIUM | 6.1 | A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated … | May 13, 2026 |
| CVE-2026-8466 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing. cowboy_req:read_part/3 in … | May 13, 2026 |
| CVE-2026-44248 | MEDIUM | 5.3 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any … | May 13, 2026 |
| CVE-2026-43970 | UNKNOWN | — | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion. cow_spdy:inflate/2 in cowlib passes … | May 13, 2026 |
| CVE-2026-42587 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent … | May 13, 2026 |
| CVE-2026-42586 | MEDIUM | 6.8 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to … | May 13, 2026 |
| CVE-2026-42585 | MEDIUM | 6.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is … | May 13, 2026 |
| CVE-2026-42584 | HIGH | 7.3 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once … | May 13, 2026 |
| CVE-2026-42583 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per … | May 13, 2026 |
| CVE-2026-42582 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for … | May 13, 2026 |
| CVE-2026-42581 | MEDIUM | 5.8 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: … | May 13, 2026 |
| CVE-2026-42580 | MEDIUM | 6.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This … | May 13, 2026 |
| CVE-2026-42579 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during … | May 13, 2026 |
| CVE-2026-42578 | UNKNOWN | — | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The … | May 13, 2026 |
| CVE-2026-42577 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive … | May 13, 2026 |
| CVE-2026-42032 | UNKNOWN | — | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed … | May 13, 2026 |
| CVE-2026-42031 | UNKNOWN | — | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed … | May 13, 2026 |
| CVE-2026-41410 | UNKNOWN | — | Rejected reason: REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-40520. Reason: This candidate is a duplicate of CVE-2026-40520. Notes: All CVE users should … | May 13, 2026 |