Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified HIGH 7.5
CVE-2026-19500

The Entries component in Brainstorm Force SureForms version, less than 2.1.3, does not enforce adequate limits on user-controlled form fields or subm…

Fix unknown
Fix from $4,900 2026-08-18
Ipados MEDIUM 6.5
CVE-2026-65347

The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead t…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-65976

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messag…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.5
CVE-2026-68005

An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_req…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.9
CVE-2026-17639

Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to c…

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 8.7
CVE-2026-71491

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-o…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-59902

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessag…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-64868

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webho…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-74785

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through …

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.5
CVE-2026-74789

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed ins…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-73057

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhau…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-18549

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit…

No fix yet
Fix from $4,900 2026-08-15
Struts HIGH 7.5
CVE-2026-73634

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violatio…

Fix unknown
Fix from $4,900 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-19830

A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the…

No fix yet
Fix from $4,000 2026-08-14
Struts HIGH 7.5
CVE-2026-73633

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.5
CVE-2026-33818

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-17078

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73566

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper t…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73568

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxe…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73561

Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadD…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-73559

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vl…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73507

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDec…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-73556

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_outp…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.7
CVE-2026-73413

Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/com…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-19587

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73228

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py …

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-73216

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c pre…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.2
CVE-2026-73214

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-73215

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks …

No fix yet
Fix from $4,900 2026-08-11
Windows 11 24h2 MEDIUM 6.5
CVE-2026-65785

Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.

Fix: 10.0.26100.9106 / 10.0.26100.33222+
Fix from $4,000 2026-08-11