Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Mailpit HIGH 7.5
CVE-2026-45713

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that control…

Fix: 1.30.0+
Fix from $1,950 2026-07-20
Traffic Server HIGH 7.5
CVE-2026-59173

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from …

Fix: 9.2.14 / 10.1.3+
Fix from $1,950 2026-07-18
Jline HIGH 7.5
CVE-2026-56740

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit…

No fix yet
Fix from $1,950 2026-07-17
Jline HIGH 7.5
CVE-2026-56741

JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-49485

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementati…

No fix yet
Fix from $1,950 2026-07-17
Netty HIGH 7.5
CVE-2026-44891

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.c…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-17
Powervm Novalink HIGH 7.5
CVE-2026-9171

IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafte…

No fix yet
Fix from $1,950 2026-07-17
Zeroconf MEDIUM 6.5
CVE-2026-47183

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four QuietLog…

No fix yet
Fix from $1,600 2026-07-17
Mattermost Desktop MEDIUM 6.5
CVE-2026-9602

Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a mal…

Fix: 5.13.7 / 6.2.1+
Fix from $1,600 2026-07-17
Wazuh MEDIUM 6.5
CVE-2026-33754

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote …

Fix: 4.14.5+
Fix from $1,600 2026-07-17
H2o HIGH 7.5
CVE-2026-54340

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combin…

Fix: 2026-06-04+
Fix from $1,950 2026-07-17
Quicly HIGH 7.5
CVE-2026-44435

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure i…

Fix: 2026-05-29+
Fix from $1,950 2026-07-16
Quicly HIGH 7.5
CVE-2026-44433

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer co…

Fix: 2026-05-29+
Fix from $1,950 2026-07-16
Unclassified HIGH 8.1
CVE-2026-44019

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.3
CVE-2026-55407

Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the decode_unknown_field function in…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-55440

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/serve…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.1
CVE-2026-52890

Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /att…

Mitigation only
Fix from $1,950 2026-07-15
Nanomq HIGH 7.5
CVE-2026-36590

An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

Mitigation only
Fix from $1,950 2026-07-15
Secure Access MEDIUM 5.9
CVE-2026-33445

CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total contro…

Fix: 14.55+
Fix from $1,600 2026-07-15
Secure Access MEDIUM 5.9
CVE-2026-33443

CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over t…

Fix: 14.55+
Fix from $1,600 2026-07-15
C2pa MEDIUM 6.2
CVE-2026-48357

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack…

Fix: after 0.84.0
Fix from $1,600 2026-07-14
Twig MEDIUM 6.5
CVE-2026-46627

Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, ev…

Fix: 3.26.0+
Fix from $1,600 2026-07-14
Soup Sieve HIGH 7.5
CVE-2026-49477

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regul…

Fix: 2.8.4+
Fix from $1,950 2026-07-14
Soup Sieve HIGH 7.5
CVE-2026-49476

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unboun…

Fix: 2.8.4+
Fix from $1,950 2026-07-14
Ua Parser Js MEDIUM 5.3
CVE-2026-48125

UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular…

Fix: 2.0.10+
Fix from $1,600 2026-07-14
Unclassified HIGH 7.5
CVE-2026-47479

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 7.5
CVE-2026-47736

Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incomin…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified HIGH 7.5
CVE-2026-47476

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit…

No fix yet
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-58627

Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Symfony HIGH 7.5
CVE-2026-45756

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonP…

Fix: 7.4.12 / 8.0.12+
Fix from $1,950 2026-07-14