Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Nexusinterface HIGH 7.5
CVE-2025-70047

An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.2.

No fix yet
Fix from $1,950 2026-03-09
Yapi HIGH 7.5
CVE-2025-70059

An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2026-03-09
Quickjs HIGH 7.5
CVE-2025-69654

A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3 (2025-12-11),`qjs` …

Fix: 2025-12-11+
Fix from $1,950 2026-03-06
Binutils MEDIUM 5.0
CVE-2025-69644

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malform…

Fix: 2.46+
Fix from $1,600 2026-03-06
Binutils MEDIUM 5.5
CVE-2025-69645

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in…

No fix yet
Fix from $1,600 2026-03-06
Binutils MEDIUM 5.5
CVE-2025-69646

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error …

No fix yet
Fix from $1,600 2026-03-06
Coredns HIGH 7.5
CVE-2026-26018

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin tha…

Fix: 1.14.2+
Fix from $1,950 2026-03-06
Olivetin HIGH 7.5
CVE-2026-28789

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerabili…

Fix: after 3000.10.2
Fix from $1,950 2026-03-05
Olivetin HIGH 7.5
CVE-2026-28342

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthentic…

Fix: 3000.10.2+
Fix from $1,950 2026-03-05
Traefik HIGH 7.5
CVE-2026-26999

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing TLS h…

Fix: 2.11.38 / 3.6.9+
Fix from $1,950 2026-03-05
Markdown HIGH 7.5
CVE-2025-69534

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled Assert…

No fix yet
Fix from $1,950 2026-03-05
Jetty HIGH 7.5
CVE-2026-1605

In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-E…

Fix: 12.0.32 / 12.1.6+
Fix from $1,950 2026-03-05
Cpp Httplib HIGH 7.5
CVE-2026-28435

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::s…

Fix: 0.35.0+
Fix from $1,950 2026-03-04
Snort MEDIUM 5.8
CVE-2026-20066

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause…

Fix: 3.9.7.0+
Fix from $1,600 2026-03-04
Arubaos HIGH 7.6
CVE-2026-23809

A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationsh…

Fix: after 10.7.2.2
Fix from $1,950 2026-03-04
Mavic Mini Firmware HIGH 7.5
CVE-2026-26673

An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via the DJI E…

Fix: after 01.02.0000
Fix from $1,950 2026-03-04
Django HIGH 7.5
CVE-2026-25673

An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django calls `urllib.parse.urlsplit(…

Fix: 4.2.29 / 5.2.12+
Fix from $1,950 2026-03-03
Android CRITICAL 9.1
CVE-2025-48609

In multiple functions of MmsProvider.java, there is a possible way to arbitrarily delete files which affect telephony, SMS, and MMS functionalities d…

Mitigation only
Fix from $2,300 2026-03-02
Textream HIGH 7.5
CVE-2026-28412

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limit on concurrent connections. …

Fix: 1.5.1+
Fix from $1,950 2026-03-02
Pypdf MEDIUM 5.3
CVE-2026-28351

pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability can craft a PDF which leads …

Fix: 6.7.4+
Fix from $1,600 2026-02-27
Rebar3 HIGH 7.5
CVE-2026-21619

Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules), hexpm hex (mix_hex_api module…

Fix: 0.12.1 / 2.3.2+
Fix from $1,950 2026-02-27
Snowflake Jdbc MEDIUM 5.5
CVE-2026-3293

A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net…

Fix: 4.0.1+
Fix from $1,600 2026-02-27
Kibana HIGH 7.5
CVE-2026-26937

Uncontrolled Resource Consumption (CWE-400) in the Timelion component in Kibana can lead Denial of Service via Input Data Manipulation (CAPEC-153)

Fix: 8.19.11 / 9.2.5+
Fix from $1,950 2026-02-26
Pypdf HIGH 7.5
CVE-2026-27888

pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can craft a PDF which leads to the R…

Fix: 6.7.3+
Fix from $1,950 2026-02-26
Tinyweb HIGH 7.5
CVE-2026-27633

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via me…

Fix: 2.02+
Fix from $1,950 2026-02-26
Tinyweb HIGH 7.5
CVE-2026-27630

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack …

Fix: 2.02+
Fix from $1,950 2026-02-26
Wasmtime MEDIUM 6.5
CVE-2026-27204

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interface…

Fix: 24.0.6 / 36.0.6+
Fix from $1,600 2026-02-24
X5000r Firmware HIGH 7.5
CVE-2025-67445

TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environm…

No fix yet
Fix from $1,950 2026-02-24
Imagemagick HIGH 7.5
CVE-2026-26066

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted pr…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-02-24
Imagemagick MEDIUM 5.3
CVE-2026-24484

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,600 2026-02-24