Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified MEDIUM 5.5
CVE-2025-13466

body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An atta…

Mitigation only
Fix from $1,600 2025-11-24
Free5gc HIGH 7.5
CVE-2025-60638

An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAva…

No fix yet
Fix from $1,950 2025-11-24
Unclassified HIGH 8.7
CVE-2025-65947

thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resource leaks when querying thread…

Patch available
Fix from $1,950 2025-11-21
Revive Adserver MEDIUM 6.5
CVE-2025-55128

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An att…

Fix: 6.0.3+
Fix from $1,600 2025-11-20
Arubaos HIGH 7.5
CVE-2025-37161

A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of servic…

Fix: 10.7.2.0+
Fix from $1,950 2025-11-18
Openml.org HIGH 7.5
CVE-2025-55796

The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation…

Fix: after 2.0.20241110
Fix from $1,950 2025-11-18
Lte3301 Plus Firmware HIGH 7.5
CVE-2025-6599

An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an …

Fix: after 5.00
Fix from $1,950 2025-11-18
M Files Server MEDIUM 6.5
CVE-2025-11681

Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user…

Fix: 25.2.14524.13 / 25.8.15085.17+
Fix from $1,600 2025-11-17
Unclassified HIGH 8.7
CVE-2021-4465

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial…

No fix yet
Fix from $1,950 2025-11-14
Unclassified HIGH 8.7
CVE-2021-4467

Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. …

Mitigation only
Fix from $1,950 2025-11-14
Unclassified HIGH 8.7
CVE-2023-7326

The Epson Stylus SX510W embedded web management service fails to properly handle consecutive ampersand characters in query parameters when accessing …

No fix yet
Fix from $1,950 2025-11-12
Jose2go HIGH 7.5
CVE-2025-63811

An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encrypt…

Fix: 1.7.0+
Fix from $1,950 2025-11-12
Unclassified MEDIUM 5.5
CVE-2025-27249

Uncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may allow a denial of service. Syste…

Mitigation only
Fix from $1,600 2025-11-11
Open5gs HIGH 7.5
CVE-2025-63288

In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.

Patch available
Fix from $1,950 2025-11-10
E3 Firmware HIGH 7.5
CVE-2025-63560

An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via …

No fix yet
Fix from $1,950 2025-11-06
Libarchive MEDIUM 5.5
CVE-2025-60753

An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s subst…

Fix: after 3.8.1
Fix from $1,600 2025-11-05
Modem 5123 Firmware HIGH 7.5
CVE-2025-49494

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 5123. Misha…

Mitigation only
Fix from $1,950 2025-11-04
Ipados HIGH 7.5
CVE-2025-43462

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, w…

Fix: 26.1+
Fix from $1,950 2025-11-04
Vacation Rental Management Platform HIGH 7.5
CVE-2025-63561

Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HT…

Fix: 1.0.2+
Fix from $1,950 2025-10-31
Python MEDIUM 5.5
CVE-2025-6075

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

Fix: 3.9.0 / 3.13.11+
Fix from $1,600 2025-10-31
Unclassified CRITICAL 9.2
CVE-2025-64388

Denial of service of the web server through specific requests to this protocol

No fix yet
Fix from $2,300 2025-10-31
Unclassified HIGH 7.5
CVE-2025-30188

Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to ope…

Mitigation only
Fix from $1,950 2025-10-31
Unclassified HIGH 7.5
CVE-2025-6176

Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protect…

Mitigation only
Fix from $1,950 2025-10-31
Librechat HIGH 7.5
CVE-2025-8849

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key…

Patch available
Fix from $1,950 2025-10-31
Manageengine Exchange Reporter Plus MEDIUM 6.5
CVE-2025-5342

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

Fix: 5.7+
Fix from $1,600 2025-10-30
Unclassified HIGH 8.2
CVE-2025-10932

Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Transfer: from 2025.0.0 before 202…

Mitigation only
Fix from $1,950 2025-10-29
Bitcoin Core HIGH 7.5
CVE-2025-54604

Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).

Fix: 30.0+
Fix from $1,950 2025-10-28
Bitcoin Core HIGH 7.5
CVE-2025-54605

Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).

Fix: 30.0+
Fix from $1,950 2025-10-28
Unclassified HIGH 7.5
CVE-2025-60349

An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver.…

Mitigation only
Fix from $1,950 2025-10-28
Unclassified MEDIUM 5.5
CVE-2025-61155

The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A …

Mitigation only
Fix from $1,600 2025-10-28