Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Ws HIGH 7.5
CVE-2026-48779

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7…

Fix: 5.2.5 / 6.2.4+
Fix from $1,950 2026-06-17
Android MEDIUM 5.5
CVE-2026-28575

In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible me…

Mitigation only
Fix from $1,600 2026-06-17
Android MEDIUM 5.5
CVE-2026-0064

In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no a…

Mitigation only
Fix from $1,600 2026-06-17
Solaris HIGH 7.1
CVE-2026-46914

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. Easily explo…

Mitigation only
Fix from $1,950 2026-06-17
Jd Edwards Enterpriseone Tools CRITICAL 9.1
CVE-2026-46910

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions…

Fix: after 9.2.26.2
Fix from $2,300 2026-06-17
Enterprise Manager Base Platform HIGH 8.2
CVE-2026-46866

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions th…

Mitigation only
Fix from $1,950 2026-06-17
Mysql Router HIGH 7.5
CVE-2026-46862

Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.…

Fix: after 9.7.0
Fix from $1,950 2026-06-17
Mysql Cluster HIGH 7.5
CVE-2026-46863

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affec…

Fix: after 9.7.0
Fix from $1,950 2026-06-17
Firefox MEDIUM 6.5
CVE-2026-12325

Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbi…

Fix: 115.37.0 / 140.12.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 6.5
CVE-2026-12319

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Fix: 152.0.0+
Fix from $1,600 2026-06-16
Unclassified HIGH 7.5
CVE-2026-50882

An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

Mitigation only
Fix from $1,950 2026-06-15
Lldap HIGH 7.5
CVE-2026-50889

An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted re…

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 7.5
CVE-2026-50878

An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted reque…

No fix yet
Fix from $1,950 2026-06-15
Unclassified HIGH 7.5
CVE-2026-50879

An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST…

Mitigation only
Fix from $1,950 2026-06-15
Unclassified MEDIUM 6.5
CVE-2026-39197

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted reque…

Mitigation only
Fix from $1,600 2026-06-15
Spring Cloud Sleuth HIGH 7.5
CVE-2026-41708

In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The applicat…

Fix: 3.1.14+
Fix from $1,950 2026-06-15
Multer HIGH 7.5
CVE-2026-5079

Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form d…

Fix: 2.2.0+
Fix from $1,950 2026-06-15
Netty HIGH 7.5
CVE-2026-50011

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArra…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-12
Netty HIGH 7.5
CVE-2026-48043

Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-12
Netty MEDIUM 5.3
CVE-2026-47244

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHt…

Fix: 4.1.135 / 4.2.15+
Fix from $1,600 2026-06-12
Cxf HIGH 7.5
CVE-2026-50645

There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncon…

Fix: 4.1.7 / 4.2.2+
Fix from $1,950 2026-06-12
Netty HIGH 7.5
CVE-2026-44892

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of…

Fix: 4.2.15+
Fix from $1,950 2026-06-12
Idira Privileged Access Manager Vault HIGH 8.6
CVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Unde…

Fix: 14.0.8 / 14.2.7+
Fix from $1,950 2026-06-12
Netty HIGH 7.5
CVE-2026-44250

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-11
Netty HIGH 7.5
CVE-2026-44890

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-11
Unclassified MEDIUM 6.0
CVE-2026-45802

FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2…

Patch available
Fix from $1,600 2026-06-11
Axios HIGH 7.5
CVE-2026-44496

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line buil…

Fix: 0.32.0 / 1.16.0+
Fix from $1,950 2026-06-11
Vllm HIGH 7.5
CVE-2026-5497

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the …

Fix: 0.19.0+
Fix from $1,950 2026-06-11
Unclassified MEDIUM 5.7
CVE-2026-47734

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with pu…

Mitigation only
Fix from $1,600 2026-06-10
Unclassified HIGH 7.5
CVE-2026-46679

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an…

Mitigation only
Fix from $1,950 2026-06-10