Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified HIGH 7.5
CVE-2025-61600

Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerability in the IMAP protocol pars…

Patch available
Fix from $1,950 2025-10-02
Unclassified HIGH 8.8
CVE-2025-61595

MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce…

Patch available
Fix from $1,950 2025-10-02
Finance.js HIGH 7.5
CVE-2025-56572

An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.

No fix yet
Fix from $1,950 2025-09-30
Unclassified HIGH 7.5
CVE-2025-11149

This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception …

Patch available
Fix from $1,950 2025-09-30
Unclassified HIGH 7.5
CVE-2025-56233

Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, Openindiana has a w…

Mitigation only
Fix from $1,950 2025-09-29
Unclassified HIGH 7.5
CVE-2025-56234

AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST packets, PLC AT_NA2000 has a w…

Mitigation only
Fix from $1,950 2025-09-29
Unclassified HIGH 7.5
CVE-2024-57412

An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets.

Mitigation only
Fix from $1,950 2025-09-29
Tensorflow HIGH 7.5
CVE-2025-55559

An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D.

No fix yet
Fix from $1,950 2025-09-25
Pytorch HIGH 7.5
CVE-2025-55560

An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense(…

Fix: after 2.7.0
Fix from $1,950 2025-09-25
Unclassified HIGH 7.5
CVE-2025-57446

An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a denial of service (DoS) via a cra…

Mitigation only
Fix from $1,950 2025-09-25
Pytorch HIGH 7.5
CVE-2025-55558

A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-to…

Fix: after 2.7.0
Fix from $1,950 2025-09-25
Rack HIGH 7.5
CVE-2025-59830

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &,…

Fix: 2.2.18+
Fix from $1,950 2025-09-25
Pytorch HIGH 7.5
CVE-2025-55551

An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.

Fix: after 2.8.0
Fix from $1,950 2025-09-25
Apidoc Core HIGH 7.5
CVE-2025-57317

apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess fun…

Fix: after 0.15.0
Fix from $1,950 2025-09-25
Iotdb HIGH 7.5
CVE-2025-48392

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to…

Fix: 2.0.5+
Fix from $1,950 2025-09-24
Transformers HIGH 7.5
CVE-2025-6921

The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay …

Fix: 4.53.0+
Fix from $1,950 2025-09-23
Unclassified HIGH 7.5
CVE-2025-57440

The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands for contro…

Mitigation only
Fix from $1,950 2025-09-22
Rexml MEDIUM 5.3
CVE-2025-58767

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. I…

Fix: 3.4.2+
Fix from $1,600 2025-09-17
Thorium HIGH 7.5
CVE-2025-35432

CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages …

Patch available
Fix from $1,950 2025-09-17
Oneblog HIGH 7.5
CVE-2025-56264

The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.

No fix yet
Fix from $1,950 2025-09-16
Ipados MEDIUM 5.5
CVE-2025-43295

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 1…

Fix: 14.8 / 15.7+
Fix from $1,600 2025-09-15
Digital Experience Platform HIGH 7.5
CVE-2025-43796

Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not li…

Fix: 7.4.3.102 / 2023.Q3.5+
Fix from $1,950 2025-09-12
Hono MEDIUM 5.3
CVE-2025-59139

Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middlewar…

Fix: 4.9.7+
Fix from $1,600 2025-09-12
Unclassified MEDIUM 5.3
CVE-2025-48039

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Ex…

Patch available
Fix from $1,600 2025-09-11
Unclassified MEDIUM 6.9
CVE-2025-48040

Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is ass…

Patch available
Fix from $1,600 2025-09-11
Unclassified HIGH 7.1
CVE-2025-48041

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This v…

Patch available
Fix from $1,950 2025-09-11
Unclassified MEDIUM 5.3
CVE-2025-48038

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Ex…

Patch available
Fix from $1,600 2025-09-11
Unclassified HIGH 7.4
CVE-2025-20340

A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to…

Mitigation only
Fix from $1,950 2025-09-10
Workplace Desktop HIGH 7.5
CVE-2025-49460

Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network acce…

Fix: 6.3.14 / 6.4.12+
Fix from $1,950 2025-09-09
Open5gs HIGH 7.5
CVE-2025-52322

An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (…

Fix: after 2.7.2
Fix from $1,950 2025-09-09