Skip to main content

CWE archive

CWE-834 CVEs

Programmatic archive

109 CVEs tagged with CWE-8340 Critical, 36 High, 72 Medium, 1 Low, 0 Unrated.

CVE-2026-64641

Published Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applicatio…

CVSS 8.2 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-50171

Published Jun 22, 2026

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45680

Published Jun 2, 2026

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observation…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-48156

Published May 28, 2026

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-41313

Published Apr 22, 2026

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. Thi…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-41168

Published Apr 22, 2026

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF which leads to long runtimes. Thi…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-40347

Published Apr 18, 2026

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests wi…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34043

Published Mar 31, 2026

Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-27025

Published Feb 20, 2026

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory cons…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-67726

Published Dec 12, 2025

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potent…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55181

Published Dec 2, 2025

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and uncondi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62707

Published Oct 22, 2025

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requ…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-56571

Published Sep 30, 2025

Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6714

Published Jul 7, 2025

MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-4227

Published Jan 15, 2025

In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which ca…

CVSS 7.5 · High

CVE-2022-48939

Published Aug 22, 2024

In the Linux kernel, the following vulnerability has been resolved: bpf: Add schedule points in batch ops syzbot reported various soft lockups caused by bpf batch operations.…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42237

Published Aug 7, 2024

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Validate payload length before processing block Move the payload length check in cs_dsp_loa…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42071

Published Jul 29, 2024

In the Linux kernel, the following vulnerability has been resolved: ionic: use dev_consume_skb_any outside of napi If we're not in a NAPI softirq context, we need to be careful…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4603

Published May 16, 2024

Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_ch…

CVSS 5.3 · Medium

CVE-2024-0842

Published Feb 9, 2024

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-49316

Published Nov 27, 2023

In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4043

Published Nov 3, 2023

In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5632

Published Oct 18, 2023

In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 109 CVEsPage 1 of 5