Skip to main content

CWE archive

CWE-606 CVEs

Programmatic archive

34 CVEs tagged with CWE-6060 Critical, 16 High, 17 Medium, 1 Low, 0 Unrated.

CVE-2026-55731

Published Jul 24, 2026

Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unau…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-33800

Published Jul 9, 2026

An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-15172

Published Jul 8, 2026

FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-11972

Published Jun 23, 2026

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

CVSS 8.2 · High
evidence mentions
10
Buzz score
39.0

CVE-2026-10143

Published Jun 10, 2026

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the clien…

CVSS 8.7 · High
evidence mentions
12
Buzz score
40.1
Vendor/product tagsBeta · best-effort

CVE-2026-41986

Published Jun 9, 2026

Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 2.4 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-27145

Published Jun 2, 2026

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute…

CVSS 6.5 · Medium
evidence mentions
42
Buzz score
50.0

CVE-2026-5950

Published May 20, 2026

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2026-42561

Published May 13, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing…

CVSS 7.5 · High
evidence mentions
9
Buzz score
36.0

CVE-2026-44289

Published May 13, 2026

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf da…

CVSS 7.5 · High
evidence mentions
6
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2026-39820

Published May 7, 2026

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

CVSS 7.5 · High
evidence mentions
30
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-33814

Published May 7, 2026

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

CVSS 7.5 · High
evidence mentions
19
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-41606

Published Apr 28, 2026

Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CVSS 5.3 · Medium
evidence mentions
13
Buzz score
45.9
Vendor/product tagsBeta · best-effort

CVE-2026-33891

Published Mar 27, 2026

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in th…

CVSS 7.5 · High
evidence mentions
11
Buzz score
42.9
Vendor/product tagsBeta · best-effort

CVE-2026-1519

Published Mar 25, 2026

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaf…

CVSS 7.5 · High
evidence mentions
32
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2019-25624

Published Mar 23, 2026

Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Att…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-27689

Published Mar 10, 2026

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a re…

CVSS 7.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2025-65518

Published Jan 8, 2026

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted req…

CVSS 7.5 · High
evidence mentions
5
Buzz score
35.9
Vendor/product tagsBeta · best-effort

CVE-2025-42930

Published Sep 9, 2025

SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive res…

CVSS 6.5 · Medium

CVE-2024-13931

Published May 22, 2025

Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: thr…

CVSS 7.5 · High

CVE-2024-13930

Published May 22, 2025

An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator credentials become compromised This issue a…

CVSS 5.9 · Medium

CVE-2025-32399

Published May 7, 2025

An Unchecked Input for Loop Condition in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to cause IO devices that use the library to enter an infinite loop by sending a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 34 CVEsPage 1 of 2