CVEs classified under CWE-606, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (23)
CVE-2026-20301 — CVSS 8.6 (high): A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software…
CVE-2026-27689 — CVSS 7.7 (high): Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and…
CVE-2026-62901 — CVSS 7.5 (high): Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-1519 — CVSS 7.5 (high): If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU…
CVE-2025-43801 — CVSS 7.5 (high): Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and…
CVE-2024-34486 — CVSS 7.5 (high): OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPQueueProp.len=0.
CVE-2024-13931 — CVSS 7.2 (high): Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised…
CVE-2026-55731: Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD…
CVE-2026-68077 — CVSS 6.5 (medium): An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range…
CVE-2026-67554 — CVSS 6.5 (medium): An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range…
CVE-2026-66276 — CVSS 6.5 (medium): An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range…
CVE-2026-33800 — CVSS 6.5 (medium): An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows…
CVE-2026-27145 — CVSS 6.5 (medium): (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This…
CVE-2026-0243 — CVSS 6.5 (medium): A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a network…
CVE-2025-42930 — CVSS 6.5 (medium): SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters…
CVE-2019-25624 — CVSS 6.2 (medium): Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed…
CVE-2023-6237 — CVSS 5.9 (medium): Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function…
CVE-2026-15172 — CVSS 5.5 (medium): FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
CVE-2026-71439: Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1…
CVE-2026-5950 — CVSS 5.3 (medium): An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote…
CVE-2024-4603 — CVSS 5.3 (medium): Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions…
CVE-2024-13930 — CVSS 4.9 (medium): An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if session administrator…
CVE-2026-41986 — CVSS 2.4 (low): Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.