Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Arubaos HIGH 7.5
CVE-2026-23824

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnera…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Unclassified HIGH 7.5
CVE-2026-44167

phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RS…

Patch available
Fix from $1,950 2026-05-12
Dovecot MEDIUM 6.5
CVE-2026-40016

Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of …

Fix: 2.4.4 / 3.1.5+
Fix from $1,600 2026-05-12
Ipados MEDIUM 6.2
CVE-2026-43653

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 1…

Fix: 14.8.7 / 18.7.9+
Fix from $1,600 2026-05-11
macOS HIGH 7.5
CVE-2026-28908

A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Taho…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Ipados HIGH 7.5
CVE-2026-28872

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26…

Fix: 18.7.9 / 26.4+
Fix from $1,950 2026-05-11
Unclassified MEDIUM 5.3
CVE-2026-8319

A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_rel…

Mitigation only
Fix from $1,600 2026-05-11
Cowlib HIGH 7.5
CVE-2026-7790

Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding …

Fix: 2.16.1+
Fix from $1,950 2026-05-11
Unclassified HIGH 7.5
CVE-2026-31247

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without…

Mitigation only
Fix from $1,950 2026-05-11
Identity Server HIGH 8.6
CVE-2025-10470

The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to un…

Fix: 7.0.0.121+
Fix from $1,950 2026-05-11
Open5gs HIGH 7.5
CVE-2026-8187

A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executi…

Fix: after 2.7.7
Fix from $1,950 2026-05-09
Unclassified MEDIUM 6.3
CVE-2026-42343

FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and …

Mitigation only
Fix from $1,600 2026-05-08
Unclassified HIGH 7.1
CVE-2026-42212

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Op…

Patch available
Fix from $1,950 2026-05-08
Dash Uploader HIGH 7.5
CVE-2026-38361

Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/…

Fix: after 0.6.1
Fix from $1,950 2026-05-08
Unclassified HIGH 7.5
CVE-2024-27686

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet d…

No fix yet
Fix from $1,950 2026-05-08
Unclassified MEDIUM 5.3
CVE-2022-26523

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrar…

Mitigation only
Fix from $1,600 2026-05-08
Gpac MEDIUM 5.5
CVE-2026-8124

A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. T…

Fix: after 26.02.0
Fix from $1,600 2026-05-08
Unclassified HIGH 7.5
CVE-2025-65122

Regex Denial of Service in youtube-regex npm package through version 1.0.5.

Mitigation only
Fix from $1,950 2026-05-07
Unclassified MEDIUM 6.9
CVE-2026-32686

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not boun…

Patch available
Fix from $1,600 2026-05-07
Opentelemetry.exporter.zipkin MEDIUM 5.3
CVE-2026-41310

OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cach…

Fix: 1.15.3+
Fix from $1,600 2026-05-06
Unclassified HIGH 7.5
CVE-2026-34473

Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q…

Mitigation only
Fix from $1,950 2026-05-06
React Server Dom Parcel HIGH 7.5
CVE-2026-23870

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to serv…

Fix: after 19.2.5
Fix from $1,950 2026-05-06
Coredns HIGH 7.5
CVE-2026-32936

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter va…

Fix: 1.14.3+
Fix from $1,950 2026-05-05
Thrift HIGH 7.3
CVE-2026-43870

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in…

Fix: 0.23.0+
Fix from $1,950 2026-05-05
Prometheus HIGH 7.5
CVE-2026-42154

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) …

Fix: 3.5.3 / 3.11.3+
Fix from $1,950 2026-05-04
Unclassified HIGH 7.5
CVE-2026-37459

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UP…

Patch available
Fix from $1,950 2026-05-04
Unclassified MEDIUM 5.9
CVE-2025-70071

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()

Mitigation only
Fix from $1,600 2026-05-04
Unclassified HIGH 7.5
CVE-2025-70069

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method

Mitigation only
Fix from $1,950 2026-05-04
Unclassified HIGH 7.5
CVE-2026-42467

An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Binary_Data_Transfer_DM…

Mitigation only
Fix from $1,950 2026-05-01
Neethi HIGH 7.5
CVE-2026-42403

Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (wher…

Fix: 3.2.2+
Fix from $1,950 2026-05-01