Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Digital Experience Platform HIGH 7.5
CVE-2025-62260

Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older uns…

Fix: 7.4.3.99+
Fix from $1,950 2025-10-27
Unclassified MEDIUM 5.9
CVE-2025-12194

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion …

Mitigation only
Fix from $1,600 2025-10-24
Unclassified MEDIUM 6.2
CVE-2025-60419

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a craft…

Mitigation only
Fix from $1,600 2025-10-24
Authlib MEDIUM 6.5
CVE-2025-62706

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFL…

Fix: 1.6.5+
Fix from $1,600 2025-10-22
Solaris MEDIUM 6.5
CVE-2025-53068

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable…

Mitigation only
Fix from $1,600 2025-10-21
Mysql Server MEDIUM 5.5
CVE-2025-53053

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4…

Fix: after 9.4.0
Fix from $1,600 2025-10-21
Mysql Server MEDIUM 5.5
CVE-2025-53054

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 an…

Fix: after 9.4.0
Fix from $1,600 2025-10-21
Peoplesoft Enterprise Peopletools HIGH 7.5
CVE-2025-53050

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are af…

Fix: after 8.62
Fix from $1,950 2025-10-21
Processwire MEDIUM 6.5
CVE-2025-60790

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits…

Fix: after 3.0.246
Fix from $1,600 2025-10-21
Unclassified HIGH 7.5
CVE-2025-61301

Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submit sample…

Mitigation only
Fix from $1,950 2025-10-20
Unclassified CRITICAL 9.8
CVE-2025-61303

Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral an…

Mitigation only
Fix from $2,300 2025-10-20
Exynos 1080 Firmware HIGH 7.5
CVE-2024-55568

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 24…

Mitigation only
Fix from $1,950 2025-10-20
Exynos W920 Firmware HIGH 7.5
CVE-2025-26782

An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14…

Mitigation only
Fix from $1,950 2025-10-20
Openbao HIGH 7.5
CVE-2025-59043

OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significa…

Fix: 2.4.1+
Fix from $1,950 2025-10-17
Unclassified MEDIUM 5.5
CVE-2025-33177

NVIDIA Jetson Linux and IGX OS contain a vulnerability in NvMap, where improper tracking of memory allocations could allow a local attacker to cause …

Mitigation only
Fix from $1,600 2025-10-14
Unclassified HIGH 7.5
CVE-2025-60536

An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Service (DoS) via uploading a craf…

Mitigation only
Fix from $1,950 2025-10-14
Windows 10 1809 HIGH 7.5
CVE-2025-59502

Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.

Fix: 10.0.17763.7792 / 10.0.19044.6332+
Fix from $1,950 2025-10-14
Unclassified MEDIUM 6.5
CVE-2025-37148

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of s…

Mitigation only
Fix from $1,600 2025-10-14
Unclassified MEDIUM 6.0
CVE-2025-37139

A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploi…

Mitigation only
Fix from $1,600 2025-10-14
Furbo 360 Dog Camera Firmware MEDIUM 6.5
CVE-2025-11635

A weakness has been identified in Tomofun Furbo 360 up to FB0035_FW_036. This vulnerability affects unknown code of the component File Upload. This m…

Fix: after 036
Fix from $1,600 2025-10-12
Rack HIGH 7.5
CVE-2025-61919

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into mem…

Fix: 2.2.20 / 3.1.18+
Fix from $1,950 2025-10-10
Authlib HIGH 7.5
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JW…

Fix: 1.6.5+
Fix from $1,950 2025-10-10
Junos Space HIGH 7.5
CVE-2025-59975

An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an unauthenticated network-based…

Fix: 22.2+
Fix from $1,950 2025-10-09
Junos Os Evolved MEDIUM 6.5
CVE-2025-52961

An Uncontrolled Resource Consumption vulnerability in the Connectivity Fault Management (CFM) daemon and the Connectivity Fault Management Manager (c…

No fix yet
Fix from $1,600 2025-10-09
Rack HIGH 7.5
CVE-2025-61771

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (…

Fix: 2.2.19 / 3.1.17+
Fix from $1,950 2025-10-07
Rack HIGH 7.5
CVE-2025-61772

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data …

Fix: 2.2.19 / 3.1.17+
Fix from $1,950 2025-10-07
Rack HIGH 7.5
CVE-2025-61770

Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` buffers the entire multipart p…

Fix: 2.2.19 / 3.1.17+
Fix from $1,950 2025-10-07
Assimp MEDIUM 5.5
CVE-2025-11274

A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/cod…

No fix yet
Fix from $1,600 2025-10-05
Qsync Central MEDIUM 6.5
CVE-2025-52867

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can the…

Fix: 5.0.0.2+
Fix from $1,600 2025-10-03
65c655 Firmware HIGH 7.5
CVE-2025-55972

A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Denial of Service (DoS) condition…

No fix yet
Fix from $1,950 2025-10-03