Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Jackson Databind HIGH 7.5
CVE-2026-50193

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a poten…

Fix: 2.14.0+
Fix from $1,950 2026-06-23
Langflow HIGH 7.5
CVE-2026-55446

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request …

Fix: 1.0.19+
Fix from $1,950 2026-06-23
Langflow CRITICAL 9.3
CVE-2026-55450EPSS 12%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to…

Fix: 1.9.1+
Fix from $2,300 2026-06-23
Unclassified HIGH 7.5
CVE-2025-61025

An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st…

Mitigation only
Fix from $1,950 2026-06-23
Unclassified HIGH 7.5
CVE-2026-56248

Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Lev…

No fix yet
Fix from $1,950 2026-06-23
Go HIGH 7.5
CVE-2023-54365

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard libr…

Fix: 1.20.10 / 1.21.3+
Fix from $1,950 2026-06-23
Pypdf MEDIUM 5.5
CVE-2026-49461

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to larg…

Fix: 6.12.2+
Fix from $1,600 2026-06-22
Python Multipart HIGH 7.5
CVE-2026-53539

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParse…

Fix: 0.0.30+
Fix from $1,950 2026-06-22
Angular MEDIUM 6.1
CVE-2026-50171

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r…

Fix: 19.2.23 / 20.3.22+
Fix from $1,600 2026-06-22
Grafana HIGH 7.5
CVE-2026-42127

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memor…

Fix: after 13.0.1
Fix from $1,950 2026-06-22
Websphere Application Server HIGH 7.5
CVE-2026-9071

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-22
Websphere Application Server HIGH 7.5
CVE-2026-9320

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of …

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $1,950 2026-06-22
Angular HIGH 7.5
CVE-2026-54268

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, …

Fix: 20.3.25 / 21.2.17+
Fix from $1,950 2026-06-22
Js Toml HIGH 7.5
CVE-2026-49293

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / bin…

Fix: 1.1.1+
Fix from $1,950 2026-06-19
Unclassified HIGH 7.5
CVE-2026-9375

urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issu…

Patch available
Fix from $1,950 2026-06-19
Tempo MEDIUM 6.5
CVE-2026-27878

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting …

Fix: 2.8.4 / 2.9.2+
Fix from $1,600 2026-06-19
Node.js HIGH 7.5
CVE-2026-48937

A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supp…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 7.5
CVE-2025-53114

CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0.0 through 7.0.18, and 8.0.0 …

Patch available
Fix from $1,950 2026-06-18
Unclassified HIGH 8.7
CVE-2025-32392

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, AutoGPT's…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 8.7
CVE-2025-32422

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `StepThro…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 8.7
CVE-2025-32424

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, Screensho…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 7.1
CVE-2025-32436

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `AddAudio…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified HIGH 8.7
CVE-2025-32437

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `MediaDur…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified MEDIUM 6.5
CVE-2026-44645

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the renderLimit option can b…

Patch available
Fix from $1,600 2026-06-17
Unclassified HIGH 7.5
CVE-2026-45357

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime i…

Patch available
Fix from $1,950 2026-06-17
Unclassified HIGH 7.5
CVE-2026-50196

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eu…

Patch available
Fix from $1,950 2026-06-17
Unclassified MEDIUM 5.3
CVE-2026-48990

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through…

No fix yet
Fix from $1,600 2026-06-17
Markdown It MEDIUM 5.3
CVE-2026-48988

markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadr…

Fix: 14.2.0+
Fix from $1,600 2026-06-17
Undici HIGH 7.5
CVE-2026-9675

Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A…

Fix: 8.5.0+
Fix from $1,950 2026-06-17
Undici HIGH 7.5
CVE-2026-12151

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on th…

Fix: 6.27.0 / 7.28.0+
Fix from $1,950 2026-06-17