Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Twisted HIGH 7.5
CVE-2026-42304

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to …

Fix: 26.4.0+
Fix from $1,950 2026-05-13
Grafana MEDIUM 6.5
CVE-2026-33378

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-resta…

Fix: 11.6.14 / 12.2.8+
Fix from $1,600 2026-05-13
Netty HIGH 7.5
CVE-2026-44248

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section i…

Fix: 4.1.133 / 4.2.13+
Fix from $1,950 2026-05-13
Netty HIGH 7.5
CVE-2026-42587

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxA…

Fix: 4.1.133 / 4.2.13+
Fix from $1,950 2026-05-13
Netty CRITICAL 9.1
CVE-2026-42579

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC…

Fix: 4.1.133 / 4.2.13+
Fix from $2,300 2026-05-13
Netty HIGH 7.5
CVE-2026-42583

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of…

Fix: 4.1.133 / 4.2.13+
Fix from $1,950 2026-05-13
Hono MEDIUM 6.5
CVE-2026-44456

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize…

Fix: 4.12.16+
Fix from $1,600 2026-05-13
Unclassified HIGH 7.5
CVE-2026-44296

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow s…

Patch available
Fix from $1,950 2026-05-12
Unclassified HIGH 7.5
CVE-2026-44241

Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.…

Patch available
Fix from $1,950 2026-05-12
Unclassified HIGH 7.5
CVE-2026-42544

Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a We…

Mitigation only
Fix from $1,950 2026-05-12
Unclassified HIGH 7.5
CVE-2026-44240

basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel mul…

Mitigation only
Fix from $1,950 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34677

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34678

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
C2pa HIGH 7.5
CVE-2026-34665

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou…

Fix: 0.7.1 / 0.80.1+
Fix from $1,950 2026-05-12
C2pa MEDIUM 6.2
CVE-2026-34673

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou…

Fix: 0.7.1 / 0.80.1+
Fix from $1,600 2026-05-12
Commerce HIGH 7.5
CVE-2026-34650EPSS 16%

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12
Commerce HIGH 7.5
CVE-2026-34651

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12
Commerce HIGH 7.5
CVE-2026-34648EPSS 23%

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12
Commerce HIGH 7.5
CVE-2026-34649EPSS 14%

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2026-05-12
Arubaos HIGH 7.5
CVE-2026-23824

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnera…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Unclassified HIGH 7.5
CVE-2026-44167

phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RS…

Patch available
Fix from $1,950 2026-05-12
Dovecot MEDIUM 6.5
CVE-2026-40016

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of …

Fix: 2.4.4 / 3.1.5+
Fix from $1,600 2026-05-12
Ipados MEDIUM 6.2
CVE-2026-43653

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 1…

Fix: 14.8.7 / 18.7.9+
Fix from $1,600 2026-05-11
macOS HIGH 7.5
CVE-2026-28908

A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Taho…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Ipados HIGH 7.5
CVE-2026-28872

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26…

Fix: 18.7.9 / 26.4+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-8319

A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_rel…

Mitigation only
Fix from $1,600 2026-05-11
Cowlib HIGH 7.5
CVE-2026-7790

Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding …

Fix: 2.16.1+
Fix from $1,950 2026-05-11
Unclassified HIGH 7.5
CVE-2026-31247

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without…

Mitigation only
Fix from $1,950 2026-05-11
Identity Server HIGH 8.6
CVE-2025-10470

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to un…

Fix: 7.0.0.121+
Fix from $1,950 2026-05-11
Open5gs HIGH 7.5
CVE-2026-8187

A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executi…

Fix: after 2.7.7
Fix from $1,950 2026-05-09