Skip to main content

CWE archive

CWE-674 CVEs

Programmatic archive

464 CVEs tagged with CWE-6746 Critical, 196 High, 232 Medium, 30 Low, 0 Unrated.

CVE-2026-2641

Published Feb 18, 2026

A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpression/parseExprList of the file parsers/v.c of the component V…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2025-70957

Published Feb 13, 2026

A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises from the handling of external arguments passed to locally e…

CVSS 7.5 · High

CVE-2025-70955

Published Feb 13, 2026

A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems from the improper handling of vmstate and continuation jump…

CVSS 7.5 · High

CVE-2026-1849

Published Feb 10, 2026

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the serve…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23066

Published Feb 4, 2026

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recvmsg() unconditional requeue If rxrpc_recvmsg() fails because MSG_DONTWAIT was specified but th…

CVSS 7.8 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2025-36001

Published Jan 30, 2026

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specia…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-22260

Published Jan 27, 2026

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-55095

Published Jan 27, 2026

The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended partition entry in the partit…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50537

Published Jan 26, 2026

Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the Rule…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-24401

Published Jan 24, 2026

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmen…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-0994

Published Jan 23, 2026

A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google…

CVSS 8.2 · High
evidence mentions
19
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-21500

Published Jan 7, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vu…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2025-68950

Published Dec 30, 2025

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68618

Published Dec 30, 2025

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a D…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67899

Published Dec 14, 2025

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

CVSS 2.9 · Low

CVE-2025-59789

Published Dec 1, 2025

Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1.15.0) on all platforms allows remote attackers to make the server crash via sending deep recursive json…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66031

Published Nov 26, 2025

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and bel…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9624

Published Nov 25, 2025

A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36158

Published Nov 20, 2025

IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from files due to uncontrolled recursive directory copying.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40090

Published Oct 30, 2025

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix recursive locking in RPC handle list access Since commit 305853cce3794 ("ksmbd: Fix race condition…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11896

Published Oct 16, 2025

In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stack overflow.

CVSS 2.1 · Low
Showing 126-150 of 464 CVEsPage 6 of 19