Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
A3002r Firmware HIGH 7.5
CVE-2025-55587

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnera…

No fix yet
Fix from $1,950 2025-08-18
Linux Kernel HIGH 7.5
CVE-2025-38501

In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connec…

Fix: 6.1.148 / 6.6.102+
Fix from $1,950 2025-08-16
Unclassified MEDIUM 6.5
CVE-2025-50861

The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without auth…

Mitigation only
Fix from $1,600 2025-08-14
Brpc HIGH 7.5
CVE-2025-54472

Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi…

Fix: 1.14.1+
Fix from $1,950 2025-08-14
Pypdf HIGH 7.5
CVE-2025-55197

pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. …

Fix: 6.0.0+
Fix from $1,950 2025-08-13
Wf2880 Firmware HIGH 7.5
CVE-2025-50615

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgitest.cgi file. Attackers can tr…

No fix yet
Fix from $1,950 2025-08-13
Windows 10 1507 HIGH 7.5
CVE-2025-53722EPSS 18%

Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.

Fix: 10.0.10240.21100 / 10.0.14393.8330+
Fix from $1,950 2025-08-12
Unclassified MEDIUM 5.7
CVE-2025-26472

Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authen…

Mitigation only
Fix from $1,600 2025-08-12
Sinec Traffic Analyzer MEDIUM 5.5
CVE-2025-40766

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker contai…

Fix: 3.0+
Fix from $1,600 2025-08-12
Unclassified MEDIUM 5.3
CVE-2025-55152

oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and …

Patch available
Fix from $1,600 2025-08-09
Unclassified HIGH 8.7
CVE-2025-54884

Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and…

Patch available
Fix from $1,950 2025-08-06
Bento4 MEDIUM 5.9
CVE-2025-8537

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetData…

Fix: after 1.6.0-641
Fix from $1,600 2025-08-05
Copyparty HIGH 7.5
CVE-2025-54796

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this f…

Fix: 1.18.9+
Fix from $1,950 2025-08-02
Materialx HIGH 7.5
CVE-2025-53012

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, ne…

Patch available
Fix from $1,950 2025-08-01
Unclassified MEDIUM 5.3
CVE-2025-54575

ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment e…

Patch available
Fix from $1,600 2025-07-30
Unclassified MEDIUM 6.9
CVE-2025-54572

The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability ex…

Patch available
Fix from $1,600 2025-07-30
macOS MEDIUM 5.5
CVE-2025-43235

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service.

Fix: 15.6+
Fix from $1,600 2025-07-30
macOS CRITICAL 9.8
CVE-2025-43193

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app m…

Fix: 13.7.7 / 14.7.7+
Fix from $2,300 2025-07-30
Nanomq HIGH 7.5
CVE-2024-42651

NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to…

No fix yet
Fix from $1,950 2025-07-29
Yarn HIGH 7.5
CVE-2025-8262

A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of …

Fix: after 1.22.22
Fix from $1,950 2025-07-28
Vbulletin MEDIUM 5.4
CVE-2025-46171

vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently la…

No fix yet
Fix from $1,600 2025-07-23
Suricata HIGH 7.5
CVE-2025-53538

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.…

Fix: 7.0.11+
Fix from $1,950 2025-07-22
Gr2200 Firmware HIGH 7.5
CVE-2025-44653

In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are …

Mitigation only
Fix from $1,950 2025-07-21
R7000 Firmware HIGH 7.5
CVE-2025-44650

In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can …

Mitigation only
Fix from $1,950 2025-07-21
Tpl 430ap Firmware HIGH 7.5
CVE-2025-44651

In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimit…

Mitigation only
Fix from $1,950 2025-07-21
Unclassified MEDIUM 6.9
CVE-2025-50057

A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote attackers to deny access to se…

Mitigation only
Fix from $1,600 2025-07-18
MySQL MEDIUM 6.5
CVE-2025-50083

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4…

Fix: after 9.3.0
Fix from $1,600 2025-07-15
MySQL MEDIUM 6.5
CVE-2025-50076

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.25. Easily ex…

Fix: after 8.0.42
Fix from $1,600 2025-07-15
MySQL MEDIUM 6.5
CVE-2025-50078

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4…

Fix: after 9.3.0
Fix from $1,600 2025-07-15
MySQL MEDIUM 6.5
CVE-2025-50082

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4…

Fix: after 9.3.0
Fix from $1,600 2025-07-15