Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Kibana MEDIUM 6.5
CVE-2026-33464

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user hol…

Fix: 8.19.16 / 9.3.5+
Fix from $1,600 2026-05-28
Nautobot MEDIUM 6.5
CVE-2026-44796

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for examp…

Fix: 2.4.33 / 3.1.2+
Fix from $1,600 2026-05-28
Pyjwt MEDIUM 5.3
CVE-2026-48525

PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64…

Fix: after 2.12.1
Fix from $1,600 2026-05-28
Pypdf MEDIUM 5.5
CVE-2026-48155

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to larg…

Fix: 6.12.0+
Fix from $1,600 2026-05-28
Volcano HIGH 7.4
CVE-2026-44247

Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size li…

Fix: 1.12.4 / 1.13.3+
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2026-45047

bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads …

Mitigation only
Fix from $1,950 2026-05-27
Langflow HIGH 7.5
CVE-2026-7528

IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.

Fix: after 1.9.0
Fix from $1,950 2026-05-27
Db2 HIGH 7.5
CVE-2026-6051

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small s…

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Db2 HIGH 7.5
CVE-2026-6052

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Websphere Application Server HIGH 7.5
CVE-2026-4410

IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Serv…

Fix: after 26.0.0.5
Fix from $1,950 2026-05-27
Unclassified MEDIUM 5.3
CVE-2026-7493

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all version…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 5.9
CVE-2026-48593

Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory exhaustion via unbounded cron …

Patch available
Fix from $1,600 2026-05-26
HTTP Server CRITICAL 9.1
CVE-2026-8856

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configura…

Fix: 8.5.5.30 / 9.0.5.29+
Fix from $2,300 2026-05-26
Unclassified HIGH 7.5
CVE-2026-9496

Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can ex…

Patch available
Fix from $1,950 2026-05-26
Hackney HIGH 7.5
CVE-2026-47071

Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies …

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney HIGH 7.5
CVE-2026-47073

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imp…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Hackney HIGH 7.5
CVE-2026-47077

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates t…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Unclassified MEDIUM 5.9
CVE-2026-42626

HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unaut…

Mitigation only
Fix from $1,600 2026-05-22
Net MEDIUM 6.5
CVE-2026-25680

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

Fix: 0.55.0+
Fix from $1,600 2026-05-22
Mattermost Server HIGH 7.5
CVE-2026-5308

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP…

Fix: 10.11.15 / 11.4.5+
Fix from $1,950 2026-05-22
Mattermost Server MEDIUM 6.5
CVE-2026-5755

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset …

Fix: 10.11.15 / 11.4.5+
Fix from $1,600 2026-05-22
Authoritative HIGH 7.5
CVE-2026-42001

Insufficient Validation of Autoprimary SOA Queries

Fix: 4.9.15 / 5.0.5+
Fix from $1,950 2026-05-21
Misp HIGH 7.5
CVE-2026-9137

The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deploym…

Fix: 2.5.38+
Fix from $1,950 2026-05-20
Defender Antimalware Platform HIGH 7.5
CVE-2026-45498 KEVEPSS 63%

Microsoft Defender Denial of Service Vulnerability

Fix: 4.18.26040.7+
Fix from $1,950 2026-05-20
Triton Inference Server HIGH 7.5
CVE-2026-24215

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A succe…

Fix: 26.03+
Fix from $1,950 2026-05-20
Firefox HIGH 7.5
CVE-2026-8968

Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, T…

Fix: 140.11 / 140.11.0+
Fix from $1,950 2026-05-19
Unclassified HIGH 7.5
CVE-2026-33232

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified HIGH 7.5
CVE-2025-56352

In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. Wh…

No fix yet
Fix from $1,950 2026-05-18
Ai MEDIUM 6.5
CVE-2026-8769

A vulnerability was determined in vercel ai up to 3.0.97. The impacted element is the function createJsonResponseHandler/createJsonErrorResponseHandl…

Fix: after 3.0.97
Fix from $1,600 2026-05-17
Unclassified HIGH 7.5
CVE-2026-38728

An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.j…

Mitigation only
Fix from $1,950 2026-05-15