Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Exynos 1080 Firmware HIGH 7.5
CVE-2025-43706

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2400, 1580, 9110, W920, W930, Mo…

Mitigation only
Fix from $1,950 2026-01-05
Messagepack HIGH 7.5
CVE-2026-21452

MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing…

Patch available
Fix from $1,950 2026-01-02
Signal K Server HIGH 7.5
CVE-2025-68272

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 all…

Fix: 2.19.0+
Fix from $1,950 2026-01-01
Binutils HIGH 7.5
CVE-2025-66863

An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted …

No fix yet
Fix from $1,950 2025-12-29
Uxplay MEDIUM 6.5
CVE-2025-60458

UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls t…

Mitigation only
Fix from $1,600 2025-12-29
Libxmljs HIGH 7.5
CVE-2025-25341

A vulnerability exists in the libxmljs 1.0.11 when parsing a specially crafted XML document. Accessing the internal _ref property on entity_ref and e…

No fix yet
Fix from $1,950 2025-12-26
Avahi MEDIUM 5.5
CVE-2025-59529

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2,…

Fix: 0.9+
Fix from $1,600 2025-12-18
Unclassified MEDIUM 6.5
CVE-2025-8872

On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization…

Mitigation only
Fix from $1,600 2025-12-16
Unclassified HIGH 8.7
CVE-2023-53873

SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attac…

No fix yet
Fix from $1,950 2025-12-15
Wekan HIGH 8.2
CVE-2025-65781

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorizat…

Fix: 8.16+
Fix from $1,950 2025-12-15
Servify Express HIGH 7.5
CVE-2025-67731

Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Express server used express.json(…

Fix: 1.2+
Fix from $1,950 2025-12-12
Tornado HIGH 7.5
CVE-2025-67726

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters …

Fix: 6.5.3+
Fix from $1,950 2025-12-12
Tornado HIGH 7.5
CVE-2025-67725

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can blo…

Fix: 6.5.3+
Fix from $1,950 2025-12-12
React HIGH 7.5
CVE-2025-67779EPSS 20%

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a sp…

Fix: 14.2.35 / 15.0.7+
Fix from $1,950 2025-12-12
Unclassified HIGH 8.7
CVE-2024-58306

minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending oversized GET requests. Atta…

No fix yet
Fix from $1,950 2025-12-11
Android MEDIUM 5.5
CVE-2025-48569

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no…

No fix yet
Fix from $1,600 2025-12-08
Android MEDIUM 6.5
CVE-2025-48631

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to remote…

Mitigation only
Fix from $1,600 2025-12-08
Android HIGH 7.8
CVE-2025-48615

In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local…

Mitigation only
Fix from $1,950 2025-12-08
Android MEDIUM 5.5
CVE-2025-48603

In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local deni…

Patch available
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48590

In verifyAndGetBypass of AppOpsService.java, there is a possible method for a malicious app to prevent dialing emergency services under limited circu…

Patch available
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48576

In updateNotificationChannelGroupFromPrivilegedListener of NotificationManagerService.java, there is a possible permanent denial of service due to re…

Patch available
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48584

In multiple functions of NotificationManagerService.java, there is a possible way to bypass the per-package channel limits causing resource exhaustio…

Patch available
Fix from $1,600 2025-12-08
Logrus HIGH 7.5
CVE-2025-65637

A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than 64KB withou…

Fix: 1.8.3+
Fix from $1,950 2025-12-04
Rhino HIGH 7.5
CVE-2025-66453

Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an …

Fix: 1.7.14.1+
Fix from $1,950 2025-12-03
Python HIGH 7.5
CVE-2025-13836

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malici…

Fix: 3.10.20 / 3.11.15+
Fix from $1,950 2025-12-01
Python MEDIUM 5.5
CVE-2025-13837

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

Fix: 3.13.10 / 3.14.1+
Fix from $1,600 2025-12-01
Cups MEDIUM 5.5
CVE-2025-58436

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects …

Fix: 2.4.15+
Fix from $1,600 2025-11-29
Unclassified HIGH 8.7
CVE-2020-36872

BACnet Test Server versions up to and including 1.01 contains a remote denial of service vulnerability in its BACnet/IP BVLC packet handling. The ser…

No fix yet
Fix from $1,950 2025-11-26
Unclassified MEDIUM 6.6
CVE-2025-66019

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads …

Patch available
Fix from $1,600 2025-11-26
Echo HIGH 7.5
CVE-2025-51741

An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server to send ema…

Mitigation only
Fix from $1,950 2025-11-25