Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26897
Total
1982
Critical
8080
High
8318
Medium
CVE ID Severity Score Description Published
CVE-2026-33376 HIGH 7.4 When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate … May 13, 2026
CVE-2026-28383 MEDIUM 6.5 A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can … May 13, 2026
CVE-2026-28380 MEDIUM 6.5 Any Editor could delete any snapshot, even if they have no access to read or write them. May 13, 2026
CVE-2026-28379 MEDIUM 6.5 A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal … May 13, 2026
CVE-2026-28376 MEDIUM 6.5 The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory … May 13, 2026
CVE-2026-28374 MEDIUM 4.3 Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations. May 13, 2026
CVE-2026-0243 UNKNOWN A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to a Prisma … May 13, 2026
CVE-2026-8496 MEDIUM 6.1 A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated … May 13, 2026
CVE-2026-8466 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing. cowboy_req:read_part/3 in … May 13, 2026
CVE-2026-44248 MEDIUM 5.3 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any … May 13, 2026
CVE-2026-43970 UNKNOWN Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of service via memory exhaustion. cow_spdy:inflate/2 in cowlib passes … May 13, 2026
CVE-2026-42587 HIGH 7.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent … May 13, 2026
CVE-2026-42586 MEDIUM 6.8 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content directly to … May 13, 2026
CVE-2026-42585 MEDIUM 6.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks. This vulnerability is … May 13, 2026
CVE-2026-42584 HIGH 7.3 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once … May 13, 2026
CVE-2026-42583 HIGH 7.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of size decompressedLength (up to 32 MB per … May 13, 2026
CVE-2026-42582 HIGH 7.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for … May 13, 2026
CVE-2026-42581 MEDIUM 5.8 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: … May 13, 2026
CVE-2026-42580 MEDIUM 6.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's chunk size parser silently overflows int, enabling request smuggling attacks. This … May 13, 2026
CVE-2026-42579 HIGH 7.5 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during … May 13, 2026
CVE-2026-42578 UNKNOWN Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The … May 13, 2026
CVE-2026-42577 HIGH 7.5 Netty is an asynchronous, event-driven network application framework. From 4.2.0.Final to 4.2.13.Final , Netty's epoll transport fails to detect and close TCP connections that receive … May 13, 2026
CVE-2026-42032 UNKNOWN CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed … May 13, 2026
CVE-2026-42031 UNKNOWN CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed … May 13, 2026
CVE-2026-41410 UNKNOWN Rejected reason: REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-40520. Reason: This candidate is a duplicate of CVE-2026-40520. Notes: All CVE users should … May 13, 2026