Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Weblogic Server MEDIUM 6.5
CVE-2025-30753

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4…

Patch available
Fix from $1,600 2025-07-15
Filebrowser MEDIUM 6.5
CVE-2025-53893

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. I…

No fix yet
Fix from $1,600 2025-07-15
Cxf MEDIUM 5.6
CVE-2025-48795

Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary …

Mitigation only
Fix from $1,600 2025-07-15
Unclassified HIGH 7.5
CVE-2025-24294

The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain…

Mitigation only
Fix from $1,950 2025-07-12
Unclassified MEDIUM 5.4
CVE-2025-53636

Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs c…

Patch available
Fix from $1,600 2025-07-11
Tomcat HIGH 7.5
CVE-2025-53506

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the …

Fix: after 11.0.8
Fix from $1,950 2025-07-10
Unclassified CRITICAL 9.1
CVE-2025-53371

DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows…

Patch available
Fix from $2,300 2025-07-10
Unclassified HIGH 7.5
CVE-2025-53645

Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due …

Mitigation only
Fix from $1,950 2025-07-09
Windows 10 1507 MEDIUM 5.7
CVE-2025-49722

Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,600 2025-07-08
Windows Server 2008 HIGH 7.5
CVE-2025-49716

Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
MongoDB HIGH 7.5
CVE-2025-6714

MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when …

Fix: 6.0.23 / 7.0.20+
Fix from $1,950 2025-07-07
MongoDB MEDIUM 6.5
CVE-2025-6712

MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to ineffic…

Fix: 8.0.10+
Fix from $1,600 2025-07-07
Hyper HIGH 7.5
CVE-2025-7074

A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the f…

Fix: after 3.4.1
Fix from $1,950 2025-07-05
Q9 Firmware HIGH 8.8
CVE-2025-7070

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functio…

Fix: after 2025-06-24
Fix from $1,950 2025-07-04
Unclassified HIGH 7.5
CVE-2025-53481

Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Allocation.This issue affects M…

Mitigation only
Fix from $1,950 2025-07-04
Dpkg HIGH 8.2
CVE-2025-6297

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i…

Fix: 1.22.21+
Fix from $1,950 2025-07-01
Unclassified MEDIUM 6.5
CVE-2025-44559

An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a Denial of Serv…

No fix yet
Fix from $1,600 2025-06-27
Cpp Httplib HIGH 7.5
CVE-2025-52887

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http headers fields are passed in, the…

Patch available
Fix from $1,950 2025-06-26
Unclassified MEDIUM 5.7
CVE-2024-57708

An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign co…

Mitigation only
Fix from $1,600 2025-06-25
Rtl8762e Software Development Kit HIGH 7.5
CVE-2025-44531

An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing pub…

No fix yet
Fix from $1,950 2025-06-24
Unclassified HIGH 7.5
CVE-2025-44528

An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of Service (DoS) via sending a c…

No fix yet
Fix from $1,950 2025-06-23
Unclassified MEDIUM 5.3
CVE-2025-6493

A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/markdown.js of the component Ma…

Mitigation only
Fix from $1,600 2025-06-22
Unclassified MEDIUM 5.3
CVE-2025-6492

A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is the function getRecommendTit…

Patch available
Fix from $1,600 2025-06-22
Kitten HIGH 7.5
CVE-2025-6365

A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is th…

Fix: after 2023-05-18
Fix from $1,950 2025-06-20
Hoteldruid HIGH 7.5
CVE-2025-44203

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database …

Mitigation only
Fix from $1,950 2025-06-20
Traffic Server HIGH 7.5
CVE-2025-49763

ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. …

Fix: 9.2.11 / 10.0.6+
Fix from $1,950 2025-06-19
Digital Experience Platform HIGH 7.5
CVE-2025-3526

SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported vers…

Fix: after 7.4.3.21
Fix from $1,950 2025-06-16
Digital Experience Platform HIGH 7.5
CVE-2025-3602

Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix p…

Fix: after 2023.q3.2
Fix from $1,950 2025-06-16
Unclassified MEDIUM 5.6
CVE-2025-22242

Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method which is exposed to all minion…

Mitigation only
Fix from $1,600 2025-06-13
Windows Server 2012 HIGH 7.5
CVE-2025-33068

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.8148 / 10.0.17763.7434+
Fix from $1,950 2025-06-10