Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified HIGH 8.7
CVE-2026-46689

Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query st…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 7.5
CVE-2026-45783

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storag…

Mitigation only
Fix from $1,950 2026-06-10
Imagemagick HIGH 7.5
CVE-2026-46522

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a mis…

Fix: 6.9.13-48 / 7.1.2-23+
Fix from $1,950 2026-06-10
Imagemagick MEDIUM 5.3
CVE-2026-45664

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a…

Fix: 6.9.13-47 / 7.1.2-22+
Fix from $1,600 2026-06-10
Imagemagick MEDIUM 5.3
CVE-2026-45031

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a mis…

Fix: 6.9.13-47 / 7.1.2-22+
Fix from $1,600 2026-06-10
Kafka Python HIGH 7.5
CVE-2026-10143

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-mid…

Fix: 2.3.2+
Fix from $1,950 2026-06-10
Spring Data Commons MEDIUM 5.9
CVE-2026-41711

Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort pa…

Fix: 2.7.20 / 3.3.17+
Fix from $1,600 2026-06-10
Spring Data Commons MEDIUM 5.9
CVE-2026-41721

Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunctio…

Fix: 2.7.20 / 3.3.17+
Fix from $1,600 2026-06-10
Spring Data Commons HIGH 7.5
CVE-2026-41695

Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings ar…

Fix: 3.4.15 / 3.5.11.1+
Fix from $1,950 2026-06-10
Spring Security HIGH 7.5
CVE-2026-40988

An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of se…

Fix: 5.7.24 / 5.8.26+
Fix from $1,950 2026-06-10
Sqlfluff HIGH 7.5
CVE-2026-46374

SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.2.0, in deployments whe…

Fix: 4.2.0+
Fix from $1,950 2026-06-09
C2pa MEDIUM 6.2
CVE-2026-47902

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An atta…

Fix: after 0.80.1
Fix from $1,600 2026-06-09
C2pa MEDIUM 6.2
CVE-2026-47904

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An atta…

Fix: after 0.80.1
Fix from $1,600 2026-06-09
C2pa MEDIUM 6.2
CVE-2026-47905

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An atta…

Fix: after 0.80.1
Fix from $1,600 2026-06-09
C2pa HIGH 7.5
CVE-2026-34713

CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An atta…

Fix: after 0.80.1
Fix from $1,950 2026-06-09
Unclassified MEDIUM 6.5
CVE-2026-36724

An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:upd…

Mitigation only
Fix from $1,600 2026-06-09
Gpac HIGH 7.5
CVE-2025-52293

A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia…

No fix yet
Fix from $1,950 2026-06-09
Freeswitch HIGH 7.5
CVE-2026-49842

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.11.1+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.5
CVE-2026-49160EPSS 54%

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Asp.net Core HIGH 7.5
CVE-2026-45591

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.28 / 9.0.17+
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.1
CVE-2026-49762

Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who controls a version string to c…

Patch available
Fix from $1,600 2026-06-09
Spring Framework HIGH 7.5
CVE-2026-41842

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Fra…

Fix: 5.3.49 / 6.1.28+
Fix from $1,950 2026-06-09
Unclassified HIGH 7.5
CVE-2026-40983

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected ver…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified HIGH 7.5
CVE-2026-40984

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected ver…

Mitigation only
Fix from $1,950 2026-06-09
Directory Server MEDIUM 6.5
CVE-2026-11611

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated c…

Mitigation only
Fix from $1,600 2026-06-08
Strawberry Graphql MEDIUM 5.3
CVE-2026-47707

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to…

Fix: 0.315.7+
Fix from $1,600 2026-06-04
Strawberry Graphql MEDIUM 5.3
CVE-2026-47706

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Ap…

Fix: 0.315.7+
Fix from $1,600 2026-06-04
Serv U HIGH 7.5
CVE-2026-28318 KEVEPSS 8%

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defl…

Fix: 15.5.4+
Fix from $1,950 2026-06-04
Connect M6e 5g Firmware MEDIUM 6.5
CVE-2026-50212

Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe de…

Mitigation only
Fix from $1,600 2026-06-04
Linux Kernel HIGH 8.6
CVE-2026-46273

In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power…

Fix: 5.10.258 / 5.15.209+
Fix from $1,950 2026-06-03