Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Windows 10 1507 HIGH 7.5
CVE-2025-26673

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw…

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-26652

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Windows 10 1507 HIGH 7.5
CVE-2025-26641

Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Fix: 10.0.10240.20978 / 10.0.14393.7969+
Fix from $1,950 2025-04-08
Windows Server 2012 HIGH 7.5
CVE-2025-21174

Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ…

Fix: 10.0.14393.7969 / 10.0.17763.7136+
Fix from $1,950 2025-04-08
Elasticsearch HIGH 7.5
CVE-2024-52981

An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects co…

Fix: 7.17.24 / 8.15.1+
Fix from $1,950 2025-04-08
Kibana MEDIUM 6.5
CVE-2024-52974

An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful att…

Fix: 7.17.23 / 8.15.1+
Fix from $1,600 2025-04-08
Elasticsearch MEDIUM 6.5
CVE-2024-52980

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause…

Fix: 8.15.1+
Fix from $1,600 2025-04-08
Fluent Bit MEDIUM 5.5
CVE-2025-29478

An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.

No fix yet
Fix from $1,600 2025-04-07
Fluent Bit MEDIUM 5.5
CVE-2025-29477

An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.

No fix yet
Fix from $1,600 2025-04-04
Stream Collector HIGH 7.5
CVE-2024-56528

This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involv…

Fix: 3.3.0+
Fix from $1,950 2025-04-03
Iglu Server HIGH 7.5
CVE-2024-47212

An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can …

Fix: 0.13.1+
Fix from $1,950 2025-04-03
Unclassified HIGH 7.3
CVE-2025-27829

An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may b…

Mitigation only
Fix from $1,950 2025-04-01
Safari CRITICAL 9.8
CVE-2025-24264

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.…

Fix: 2.4 / 15.4+
Fix from $2,300 2025-03-31
macOS CRITICAL 9.8
CVE-2025-24269

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected system termi…

Fix: 15.4+
Fix from $2,300 2025-03-31
macOS CRITICAL 9.8
CVE-2025-24260

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attac…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS CRITICAL 9.8
CVE-2025-24247

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An a…

Fix: 13.7.5 / 14.7.5+
Fix from $2,300 2025-03-31
macOS MEDIUM 5.5
CVE-2025-24235

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Vent…

Fix: 13.7.5 / 14.7.5+
Fix from $1,600 2025-03-31
Ipados CRITICAL 9.8
CVE-2025-24211

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Son…

Fix: 2.4 / 13.7.5+
Fix from $2,300 2025-03-31
macOS MEDIUM 5.5
CVE-2025-24199

An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, mac…

Fix: 13.7.5 / 14.7.5+
Fix from $1,600 2025-03-31
Ipados CRITICAL 9.8
CVE-2025-24190

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sono…

Fix: 2.4 / 13.7.5+
Fix from $2,300 2025-03-31
Assimp MEDIUM 6.5
CVE-2025-3016

A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImp…

Patch available
Fix from $1,600 2025-03-31
Unclassified HIGH 7.5
CVE-2025-2586

A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent e…

Patch available
Fix from $1,950 2025-03-31
Libming HIGH 7.5
CVE-2025-29487

An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator ex…

No fix yet
Fix from $1,950 2025-03-27
Libming MEDIUM 6.5
CVE-2025-29490

libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a De…

No fix yet
Fix from $1,600 2025-03-27
Libming HIGH 7.5
CVE-2025-29484

An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator ex…

No fix yet
Fix from $1,950 2025-03-27
Oneblog MEDIUM 5.3
CVE-2025-2833

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component H…

Fix: after 2.3.9
Fix from $1,600 2025-03-27
Unclassified MEDIUM 6.5
CVE-2025-2820

An authenticated attacker can compromise the availability of the device via the network

No fix yet
Fix from $1,600 2025-03-26
Core Flight System HIGH 7.5
CVE-2025-25374

In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external applicati…

No fix yet
Fix from $1,950 2025-03-25
Redlib HIGH 7.5
CVE-2025-30160

Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (…

Fix: 0.36.0+
Fix from $1,950 2025-03-20
Gradio HIGH 7.5
CVE-2025-0187

A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to im…

No fix yet
Fix from $1,950 2025-03-20