Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Commons Configuration MEDIUM 6.5
CVE-2025-46392

Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.…

Fix: 2.0+
Fix from $1,600 2025-05-09
Jetty HIGH 7.5
CVE-2025-1948

In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_…

Fix: 12.0.17+
Fix from $1,950 2025-05-08
Rack HIGH 7.5
CVE-2025-46727

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/…

Fix: 2.2.14 / 3.0.16+
Fix from $1,950 2025-05-07
Ios Xe HIGH 8.6
CVE-2025-20162

A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interf…

Mitigation only
Fix from $1,950 2025-05-07
Harmonyos MEDIUM 5.5
CVE-2025-46593

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availabili…

No fix yet
Fix from $1,600 2025-05-06
Cpp Httplib HIGH 7.5
CVE-2025-46728

cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits o…

Fix: 0.20.1+
Fix from $1,950 2025-05-06
Linkerd MEDIUM 6.5
CVE-2025-43915

In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.0–2.16.4,…

Fix: 2.16.5 / 2.17.2+
Fix from $1,600 2025-05-05
Unclassified MEDIUM 5.5
CVE-2025-23246

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to consume unco…

Mitigation only
Fix from $1,600 2025-05-01
Elasticsearch HIGH 7.5
CVE-2024-52979

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial …

Fix: 7.17.25 / 8.16.0+
Fix from $1,950 2025-05-01
Net\ MEDIUM 6.5
CVE-2025-43857

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there i…

Fix: 0.2.5 / 0.3.9+
Fix from $1,600 2025-04-28
Unclassified MEDIUM 5.3
CVE-2025-32472

The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowl…

Mitigation only
Fix from $1,600 2025-04-28
Central Authentication Service HIGH 7.5
CVE-2025-3986

A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\cor…

Mitigation only
Fix from $1,950 2025-04-27
Zxcloud Goldendb HIGH 7.5
CVE-2025-46580

There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of busines…

Fix: 6.1.03.11+
Fix from $1,950 2025-04-27
Unclassified MEDIUM 5.7
CVE-2025-2811

A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint,…

Mitigation only
Fix from $1,600 2025-04-26
Unclassified MEDIUM 5.5
CVE-2025-27087

A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.

No fix yet
Fix from $1,600 2025-04-22
Nameless HIGH 7.1
CVE-2025-30158

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post ifram…

Fix: 2.2.0+
Fix from $1,950 2025-04-18
Nameless HIGH 7.1
CVE-2025-31118

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topi…

Fix: 2.2.0+
Fix from $1,950 2025-04-18
Vm Virtualbox MEDIUM 6.7
CVE-2025-30725

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Diff…

Patch available
Fix from $1,600 2025-04-15
Application Object Library HIGH 7.5
CVE-2025-30730

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected ar…

Fix: after 12.2.14
Fix from $1,950 2025-04-15
Mysql Server MEDIUM 6.5
CVE-2025-21577

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 an…

Fix: after 9.2.0
Fix from $1,600 2025-04-15
Mysql Cluster MEDIUM 6.5
CVE-2025-21574

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-…

Fix: after 9.2.0
Fix from $1,600 2025-04-15
Mysql Cluster MEDIUM 6.5
CVE-2025-21575

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-…

Fix: after 9.2.0
Fix from $1,600 2025-04-15
macOS MEDIUM 6.4
CVE-2023-42983

Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed w…

Fix: 14.0+
Fix from $1,600 2025-04-11
Unclassified MEDIUM 6.8
CVE-2025-27081

A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a local Denial of Service.

No fix yet
Fix from $1,600 2025-04-10
Windows Server 2012 HIGH 7.5
CVE-2025-27485

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-27486

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-27473

Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-27469

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw…

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-27470

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-26680

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08