Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified HIGH 8.7
CVE-2025-58451

Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially exponential worst-case comple…

Patch available
Fix from $1,950 2025-09-08
Open5gs HIGH 7.5
CVE-2025-52288

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) compo…

Fix: after 2.7.5
Fix from $1,950 2025-09-08
Unclassified MEDIUM 5.3
CVE-2025-58369

fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, and 3.13.0-M1 through 3.13.0-M…

Patch available
Fix from $1,600 2025-09-05
Android MEDIUM 6.2
CVE-2024-40664

In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logic error i…

Mitigation only
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-48542

In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to l…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-26463

In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a local persiste…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-26449

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no…

Patch available
Fix from $1,600 2025-09-04
Android MEDIUM 6.2
CVE-2025-26423

In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. This coul…

Patch available
Fix from $1,600 2025-09-04
Unclassified HIGH 7.1
CVE-2025-43772

Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not …

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.5
CVE-2025-36892

Denial of service

No fix yet
Fix from $1,950 2025-09-04
Ada Web Server HIGH 7.5
CVE-2025-52494

Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes during conne…

Fix: 26.0+
Fix from $1,950 2025-09-03
Unclassified MEDIUM 6.3
CVE-2024-13065

Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows Input Data Manipulation, CAP…

Mitigation only
Fix from $1,600 2025-09-03
Rust Ffmpeg HIGH 7.5
CVE-2025-57614

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allows an at…

No fix yet
Fix from $1,950 2025-09-02
Gnark HIGH 7.5
CVE-2025-58157

gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerability when computing scalar multi…

Patch available
Fix from $1,950 2025-08-29
Unclassified MEDIUM 5.3
CVE-2025-9670

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Perform…

Mitigation only
Fix from $1,600 2025-08-29
Qsync Central MEDIUM 6.5
CVE-2025-29898

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can the…

Fix: 4.5.0.7+
Fix from $1,600 2025-08-29
Asterisk MEDIUM 6.5
CVE-2025-54995

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resou…

Fix: 18.9 / 18.26.4+
Fix from $1,600 2025-08-28
Android MEDIUM 5.5
CVE-2024-49740

In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execu…

No fix yet
Fix from $1,600 2025-08-26
Smart 2k\+ Plug In Wi Fi Video Doorbell With Chime Firmware HIGH 7.5
CVE-2025-55634

Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 a…

No fix yet
Fix from $1,950 2025-08-22
Unclassified MEDIUM 5.9
CVE-2025-9341

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion …

Mitigation only
Fix from $1,600 2025-08-22
Unclassified HIGH 7.7
CVE-2025-57751

pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of …

Mitigation only
Fix from $1,950 2025-08-21
Akaunting MEDIUM 6.5
CVE-2025-55521

An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial of Service (DoS) via a crafted…

Fix: after 3.1.19
Fix from $1,600 2025-08-21
Yarn MEDIUM 5.5
CVE-2025-9308

A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such mani…

Fix: after 1.22.22
Fix from $1,600 2025-08-21
Vllm HIGH 7.5
CVE-2025-48956

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can …

Fix: 0.10.1.1+
Fix from $1,950 2025-08-21
Jetty HIGH 7.5
CVE-2025-5115

In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM fra…

Fix: after 12.0.21
Fix from $1,950 2025-08-20
Firefox HIGH 7.5
CVE-2025-9182

Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderb…

Fix: 140.2.0 / 142.0+
Fix from $1,950 2025-08-19
Firefox HIGH 7.5
CVE-2025-55029

Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed i…

Fix: 142.0+
Fix from $1,950 2025-08-19
Firefox MEDIUM 6.5
CVE-2025-55028

Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service atta…

Fix: 142.0+
Fix from $1,600 2025-08-19
A3002r Firmware HIGH 7.5
CVE-2025-55588

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability al…

No fix yet
Fix from $1,950 2025-08-18
A3002r Firmware HIGH 7.5
CVE-2025-55586

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allo…

No fix yet
Fix from $1,950 2025-08-18