Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Dompdf HIGH 7.5
CVE-2026-59941

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared …

Fix: 3.1.6+
Fix from $1,950 2026-07-28
Dompdf HIGH 7.5
CVE-2026-59942

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An at…

Fix: 3.1.6+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-14981

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-59932

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-59933

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.6
CVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards REC…

No fix yet
Fix from $1,950 2026-07-28
Tomcat HIGH 7.5
CVE-2026-66299

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through…

Fix: 9.0.121 / 10.1.58+
Fix from $1,950 2026-07-28
Unclassified HIGH 8.2
CVE-2026-66920

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursiv…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-66913

Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-42493

Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out ov…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2025-63913

An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and co…

No fix yet
Fix from $1,950 2026-07-27
React Router HIGH 7.5
CVE-2026-55685

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests t…

Fix: 7.18.0+
Fix from $1,950 2026-07-27
Ipados MEDIUM 5.5
CVE-2026-64724

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
Safari MEDIUM 6.5
CVE-2026-43804

This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS …

Fix: 26.6+
Fix from $1,600 2026-07-27
macOS MEDIUM 5.5
CVE-2026-43806

A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cau…

Fix: 26.6+
Fix from $1,600 2026-07-27
macOS MEDIUM 5.5
CVE-2026-43768

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
macOS MEDIUM 5.5
CVE-2026-28932

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8,…

Fix: 14.8.8 / 15.7.8+
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.3
CVE-2026-17501

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp …

No fix yet
Fix from $1,600 2026-07-27
Neethi HIGH 7.5
CVE-2026-66142

Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to …

Fix: 3.2.3+
Fix from $1,950 2026-07-24
Neethi HIGH 7.5
CVE-2026-66143

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies…

No fix yet
Fix from $1,950 2026-07-24
Neethi HIGH 7.5
CVE-2026-66144

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of …

Fix: 3.2.3+
Fix from $1,950 2026-07-24
Unclassified HIGH 7.5
CVE-2026-14257

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-21723

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-e…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.5
CVE-2026-38763

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.6
CVE-2026-45820

fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry dec…

No fix yet
Fix from $1,600 2026-07-22
Elasticsearch MEDIUM 6.5
CVE-2026-63263

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticat…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-22
Kibana MEDIUM 6.5
CVE-2026-63260

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker w…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Kibana MEDIUM 6.5
CVE-2026-63261

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authentica…

Fix: 8.19.19 / 9.3.8+
Fix from $1,600 2026-07-21
Netty HIGH 7.5
CVE-2026-56819

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Fina…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-21
E Business Suite HIGH 7.6
CVE-2026-62518

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a…

Fix: after 12.2.15
Fix from $1,950 2026-07-21