Skip to main content

CWE archive

CWE-835 CVEs

Programmatic archive

882 CVEs tagged with CWE-83510 Critical, 375 High, 474 Medium, 23 Low, 0 Unrated.

CVE-2026-59933

Published Jul 28, 2026

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, a…

CVSS 7.5 · High
evidence mentions
7

CVE-2026-10683

Published Jul 27, 2026

In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler gates the write_requested() callback on dw->state != CMD…

CVSS 2.4 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-66730

Published Jul 27, 2026

facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker pr…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-43871

Published Jul 27, 2026

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0. Users are…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-64611

Published Jul 23, 2026

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty mode…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-64834

Published Jul 22, 2026

FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of s…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16551

Published Jul 22, 2026

Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45820

Published Jul 22, 2026

fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFF…

CVSS 6.6 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-56852

Published Jul 21, 2026

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-59849

Published Jul 21, 2026

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are mi…

CVSS 3.1 · Low
evidence mentions
3
Buzz score
23.9

CVE-2026-54538

Published Jul 20, 2026

xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLength field within the RDP protoc…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-71397

Published Jul 18, 2026

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespace, or database level) to defin…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-45785

Published Jul 17, 2026

OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. In 3.1.3 and earlier, the BST name-lookup loop in Dir…

CVSS 6.2 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-7771

Published Jul 17, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial of serv…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-46378

Published Jul 16, 2026

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Toke…

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-13401

Published Jul 16, 2026

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state curs…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-13397

Published Jul 16, 2026

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cur…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-50324

Published Jul 14, 2026

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2026-54119

Published Jul 14, 2026

Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-62642

Published Jul 14, 2026

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TN…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-59203

Published Jul 14, 2026

Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-55865

Published Jul 9, 2026

Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no ter…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-56289

Published Jul 9, 2026

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted p…

CVSS 4.6 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 882 CVEsPage 1 of 36