Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Imagemagick HIGH 7.5
CVE-2026-24485

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD f…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,950 2026-02-24
X5000r Firmware CRITICAL 9.8
CVE-2025-70327

TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executa…

Mitigation only
Fix from $2,300 2026-02-23
Moodle MEDIUM 6.5
CVE-2026-26047

A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution tim…

Fix: 4.5.9 / 5.0.5+
Fix from $1,600 2026-02-21
Jspdf HIGH 7.5
CVE-2026-25535

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of s…

Fix: 4.2.0+
Fix from $1,950 2026-02-19
Unclassified HIGH 7.5
CVE-2019-25401

Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin configuration page. Remote a…

No fix yet
Fix from $1,950 2026-02-18
Aruba Networking Private 5g Core MEDIUM 6.5
CVE-2026-23596

A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful …

Fix: after 1.24.3.3
Fix from $1,600 2026-02-17
Iobit Unlocker MEDIUM 6.2
CVE-2025-66676

An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.

No fix yet
Fix from $1,600 2026-02-13
Traefik HIGH 7.5
CVE-2026-25949

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unau…

Fix: 3.6.8+
Fix from $1,950 2026-02-12
Webtransport Go HIGH 7.5
CVE-2026-21435

webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by …

Fix: 0.10.0+
Fix from $1,950 2026-02-12
Halo HIGH 7.5
CVE-2025-70886

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission end…

Fix: after 2.22.4
Fix from $1,950 2026-02-12
Safari MEDIUM 5.3
CVE-2026-20676

This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS …

Fix: 26.3+
Fix from $1,600 2026-02-11
Safari HIGH 7.5
CVE-2026-20652

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, ma…

Fix: 18.7.5 / 26.3+
Fix from $1,950 2026-02-11
Ipados HIGH 7.5
CVE-2026-20650

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visio…

Fix: 26.3+
Fix from $1,950 2026-02-11
macOS MEDIUM 5.5
CVE-2026-20602

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app …

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
Ipados MEDIUM 5.7
CVE-2025-46304

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
File Station MEDIUM 6.5
CVE-2025-62854

An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can th…

Fix: 5.5.6.5190+
Fix from $1,600 2026-02-11
Qsync Central MEDIUM 5.5
CVE-2025-54149

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then…

Fix: 5.0.0.4+
Fix from $1,600 2026-02-11
Qsync Central MEDIUM 5.5
CVE-2025-54150

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then…

Fix: 5.0.0.4+
Fix from $1,600 2026-02-11
Qsync Central MEDIUM 5.5
CVE-2025-54151

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then…

Fix: 5.0.0.4+
Fix from $1,600 2026-02-11
Unclassified MEDIUM 5.5
CVE-2025-70347

An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblock_size …

Mitigation only
Fix from $1,600 2026-02-10
Unclassified MEDIUM 5.5
CVE-2024-54192

An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_getplugin function at src/tcpe…

Patch available
Fix from $1,600 2026-02-10
Sliver HIGH 7.5
CVE-2026-25791

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP boo…

Fix: 1.7.0+
Fix from $1,950 2026-02-09
Bodyparser HIGH 7.5
CVE-2026-25762

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multi…

Fix: 10.1.3 / 11.0.0+
Fix from $1,950 2026-02-06
Navidrome MEDIUM 6.5
CVE-2026-25579

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome serv…

Fix: 0.60.0+
Fix from $1,600 2026-02-04
Melon HIGH 7.5
CVE-2025-71031

Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maximum length. As a result, an ex…

Fix: after 2025-01-18
Fix from $1,950 2026-02-04
Apko HIGH 7.5
CVE-2026-25140

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or…

Fix: 1.1.1+
Fix from $1,950 2026-02-04
Apko MEDIUM 5.5
CVE-2026-25122

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the …

Fix: 1.1.0+
Fix from $1,600 2026-02-04
Exynos 990 Firmware HIGH 7.5
CVE-2025-59439

An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and Modem 5123.…

Mitigation only
Fix from $1,950 2026-02-03
Unclassified MEDIUM 5.3
CVE-2025-6208

The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption due to a resource management…

Patch available
Fix from $1,600 2026-02-02
Unclassified MEDIUM 5.7
CVE-2025-7105

A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork` to fork numerous contents r…

Patch available
Fix from $1,600 2026-02-02