Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified MEDIUM 6.5
CVE-2026-70489

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backe…

No fix yet
Fix from $1,600 2026-08-04
Milo HIGH 7.5
CVE-2026-61387

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, …

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.9
CVE-2026-58042

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.2
CVE-2026-58045

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.5
CVE-2026-56846

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnera…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67978

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-69249

python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invali…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67973

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67977

An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) vi…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.1
CVE-2026-69244

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C resp…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67976

The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Den…

No fix yet
Fix from $1,950 2026-08-03
Brace Expansion HIGH 7.5
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() doe…

Fix: 1.1.18 / 2.1.4+
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.3
CVE-2026-67312

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON()…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67313

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segm…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67318

axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent w…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.5
CVE-2026-53505

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an uppe…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-53504

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtr…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.5
CVE-2026-52857

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml c…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-18358

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the inco…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-55497

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed fil…

No fix yet
Fix from $1,600 2026-07-31
Db2 MEDIUM 5.5
CVE-2026-10695

IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.

Fix: 12.1.5+
Fix from $1,600 2026-07-30
Engineering Requirements Management Doors Web Access HIGH 7.5
CVE-2024-25039

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of …

Fix: after 9.7.2.11
Fix from $1,950 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-9322

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of …

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-67437

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_au…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.2
CVE-2026-63119

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MC…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.1
CVE-2026-16543

Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-w…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.1
CVE-2026-15228

Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration…

No fix yet
Fix from $1,950 2026-07-29
Traffic Server HIGH 8.6
CVE-2026-58182

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Serv…

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-65324

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This …

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29
Traffic Server HIGH 7.5
CVE-2026-58151

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic …

Fix: 9.2.15 / 10.1.4+
Fix from $1,950 2026-07-29