Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Mysql Server MEDIUM 6.5
CVE-2026-34271

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.…

Fix: after 9.6.0
Fix from $1,600 2026-04-21
Jre MEDIUM 5.3
CVE-2026-22021

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supporte…

Mitigation only
Fix from $1,600 2026-04-21
Mysql Server MEDIUM 6.5
CVE-2026-22017

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4…

Fix: after 9.6.0
Fix from $1,600 2026-04-21
Mysql Server MEDIUM 6.5
CVE-2026-22009

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4…

Fix: after 9.6.0
Fix from $1,600 2026-04-21
Graalvm MEDIUM 6.0
CVE-2026-22003

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are a…

Mitigation only
Fix from $1,600 2026-04-21
Firefox MEDIUM 5.3
CVE-2026-6777

Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox HIGH 7.5
CVE-2026-6780

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 7.5
CVE-2026-6781

Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,950 2026-04-21
Openbao MEDIUM 6.5
CVE-2026-39396

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downlo…

Fix: 2.5.3+
Fix from $1,600 2026-04-21
Signal K Server HIGH 7.5
CVE-2026-39320

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular E…

Fix: 2.25.0+
Fix from $1,950 2026-04-21
Unclassified MEDIUM 5.3
CVE-2026-6607

A security vulnerability has been detected in lm-sys fastchat up to 0.2.36. This issue affects the function api_generate of the component Worker API …

Patch available
Fix from $1,600 2026-04-20
Python Multipart MEDIUM 5.3
CVE-2026-40347

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `mu…

Fix: 0.0.26+
Fix from $1,600 2026-04-18
Monetr HIGH 7.5
CVE-2026-40481

monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request…

Fix: 1.12.4+
Fix from $1,950 2026-04-17
Zrok HIGH 7.5
CVE-2026-40303

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-suppli…

Fix: 2.0.1+
Fix from $1,950 2026-04-17
Pillow HIGH 7.5
CVE-2026-40192

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, …

Fix: 12.2.0+
Fix from $1,950 2026-04-15
Unclassified HIGH 7.5
CVE-2026-3505

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcp…

Patch available
Fix from $1,950 2026-04-15
Unclassified HIGH 7.5
CVE-2024-33618

Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk space via n…

Mitigation only
Fix from $1,950 2026-04-15
Jellyfin MEDIUM 6.5
CVE-2026-35034

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creati…

Fix: 10.11.7+
Fix from $1,600 2026-04-14
.net HIGH 7.5
CVE-2026-33116

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a …

Fix: 8.0.26 / 9.0.15+
Fix from $1,950 2026-04-14
.net HIGH 7.5
CVE-2026-26171

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

Fix: 7.5.6 / 7.6.1+
Fix from $1,950 2026-04-14
Powerchute Serial Shutdown MEDIUM 6.5
CVE-2026-2405

CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service whe…

Fix: 1.5+
Fix from $1,600 2026-04-14
Ffmpeg HIGH 7.5
CVE-2026-30998

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of S…

Fix: after 8.0.1
Fix from $1,950 2026-04-13
Activemq HIGH 7.5
CVE-2026-39304

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do…

Fix: 5.19.4 / 6.2.4+
Fix from $1,950 2026-04-10
Unclassified MEDIUM 5.3
CVE-2026-5986

A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This man…

Mitigation only
Fix from $1,600 2026-04-09
Unclassified HIGH 7.5
CVE-2026-23869

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turb…

Mitigation only
Fix from $1,950 2026-04-08
Liquidjs MEDIUM 5.3
CVE-2026-34166

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly acco…

Fix: 10.25.3+
Fix from $1,600 2026-04-08
Kibana MEDIUM 6.5
CVE-2026-33459

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with …

Fix: 8.19.14 / 9.2.8+
Fix from $1,600 2026-04-08
Axios MEDIUM 5.9
CVE-2026-39865

Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic …

Fix: 1.13.2+
Fix from $1,600 2026-04-08
Aardvark Dns HIGH 7.5
CVE-2026-35406

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection r…

Fix: 1.17.1+
Fix from $1,950 2026-04-07
Podman Desktop CRITICAL 9.1
CVE-2026-34045

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des…

Fix: 1.26.2+
Fix from $2,300 2026-04-07