Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Neethi HIGH 7.5
CVE-2026-42402

Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documen…

Fix: 3.2.2+
Fix from $1,950 2026-05-01
Secure Access MEDIUM 5.5
CVE-2026-40951

CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows cl…

Fix: 14.50+
Fix from $1,600 2026-04-30
Unclassified HIGH 7.5
CVE-2025-46115

An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request

Mitigation only
Fix from $1,950 2026-04-30
Dbit N300 T1 Pro Firmware HIGH 7.5
CVE-2026-36957

Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-…

No fix yet
Fix from $1,950 2026-04-30
N300 Firmware HIGH 7.5
CVE-2026-36958

A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random …

No fix yet
Fix from $1,950 2026-04-30
Wazuh HIGH 8.2
CVE-2026-28221

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-ba…

Fix: 4.14.4+
Fix from $1,950 2026-04-29
Spring Framework MEDIUM 6.5
CVE-2026-22740

A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files ma…

Fix: 5.3.48 / 6.1.27+
Fix from $1,600 2026-04-29
Spring Framework MEDIUM 5.3
CVE-2026-22745

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can…

Fix: 5.3.48 / 6.1.27+
Fix from $1,600 2026-04-29
Spring Ai MEDIUM 6.5
CVE-2026-40980

In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextSt…

Fix: 1.0.6 / 1.1.5+
Fix from $1,600 2026-04-28
Unclassified HIGH 7.5
CVE-2026-30350

An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via a crafted…

Mitigation only
Fix from $1,950 2026-04-27
Marked HIGH 7.5
CVE-2026-41680

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a sp…

Fix: 18.0.2+
Fix from $1,950 2026-04-24
Unclassified MEDIUM 5.3
CVE-2026-31052

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout Authentication Flow component

No fix yet
Fix from $1,600 2026-04-24
Tempo HIGH 7.5
CVE-2026-21728

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment stra…

Fix: 2.8.4 / 2.9.2+
Fix from $1,950 2026-04-24
Basic Ftp HIGH 7.5
CVE-2026-41324

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing …

Fix: 5.3.0+
Fix from $1,950 2026-04-24
Unclassified HIGH 8.2
CVE-2026-41309

Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaus…

Patch available
Fix from $1,950 2026-04-24
Authoritative HIGH 7.5
CVE-2026-33610

A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS updat…

Fix: 4.9.14 / 5.0.4+
Fix from $1,950 2026-04-22
Hardened Images MEDIUM 5.5
CVE-2026-6844

A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by prov…

Mitigation only
Fix from $1,600 2026-04-22
Telerik Ui For Asp.net Ajax HIGH 7.5
CVE-2026-6022

In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file up…

Fix: 2026.1.421+
Fix from $1,950 2026-04-22
Unclassified HIGH 8.7
CVE-2026-41146

facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinit…

Patch available
Fix from $1,950 2026-04-22
Free5gc HIGH 7.5
CVE-2026-41135

free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak v…

Fix: 1.4.3+
Fix from $1,950 2026-04-22
Tekton Pipelines MEDIUM 6.5
CVE-2026-40924

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3…

Fix: 1.11.1+
Fix from $1,600 2026-04-21
Mysql Server MEDIUM 6.5
CVE-2026-34308

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.…

Fix: after 9.6.0
Fix from $1,600 2026-04-21
Mysql Server MEDIUM 6.5
CVE-2026-34303

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4…

Fix: after 9.6.0
Fix from $1,600 2026-04-21
Identity Manager Connector HIGH 7.5
CVE-2026-34290

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…

Mitigation only
Fix from $1,950 2026-04-21
Solaris MEDIUM 6.5
CVE-2026-34281

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily exploitab…

Mitigation only
Fix from $1,600 2026-04-21
Jre HIGH 7.5
CVE-2026-34282

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Su…

Mitigation only
Fix from $1,950 2026-04-21
Mysql Server MEDIUM 6.5
CVE-2026-34272

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.6.0. Easi…

Fix: after 9.6.0
Fix from $1,600 2026-04-21
Mysql Server MEDIUM 6.5
CVE-2026-34276

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.…

Fix: after 9.6.0
Fix from $1,600 2026-04-21
Peoplesoft Enterprise Peopletools MEDIUM 6.6
CVE-2026-34277

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected ar…

Mitigation only
Fix from $1,600 2026-04-21
Mysql Server MEDIUM 6.5
CVE-2026-34270

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.…

Fix: after 9.6.0
Fix from $1,600 2026-04-21