Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Pyasn1 HIGH 7.5
CVE-2026-59886

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u…

Fix: 0.6.4+
Fix from $1,950 2026-07-14
Pillow HIGH 7.5
CVE-2026-59200

Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize se…

Fix: 12.3.0+
Fix from $1,950 2026-07-14
Pyasn1 HIGH 7.5
CVE-2026-59884

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating …

Fix: 0.6.4+
Fix from $1,950 2026-07-14
Pyasn1 HIGH 7.5
CVE-2026-59885

pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua…

Fix: 0.6.4+
Fix from $1,950 2026-07-14
.net Framework HIGH 7.5
CVE-2026-50653

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

No fix yet
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 6.5
CVE-2026-49799

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a …

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Quiche HIGH 7.5
CVE-2026-12523

Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/…

Fix: 0.29.3+
Fix from $1,950 2026-07-14
Jetty HIGH 7.5
CVE-2024-7708

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Cont…

Fix: 10.0.23 / 11.0.23+
Fix from $1,950 2026-07-14
Unclassified HIGH 8.3
CVE-2026-58486

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bo…

Patch available
Fix from $1,950 2026-07-13
Unclassified HIGH 7.5
CVE-2026-51539

A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout…

Mitigation only
Fix from $1,950 2026-07-13
Excelize HIGH 7.5
CVE-2026-59161

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows …

Fix: 2.11.0+
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-39244

adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js lin…

No fix yet
Fix from $1,950 2026-07-10
Grafana HIGH 7.5
CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually e…

Fix: 11.6.15 / 12.2.9+
Fix from $1,950 2026-07-10
Grafana HIGH 7.5
CVE-2026-33382

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send ver…

Fix: 11.6.15 / 12.2.9+
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40007

Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap re…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-51600

Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). …

Mitigation only
Fix from $1,950 2026-07-09
Python HIGH 7.5
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processi…

Fix: 3.15.0+
Fix from $1,950 2026-07-09
Unclassified HIGH 7.5
CVE-2026-54772

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote att…

Patch available
Fix from $1,950 2026-07-08
Unclassified HIGH 7.5
CVE-2026-51535

In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.

Mitigation only
Fix from $1,950 2026-07-08
Pypdf HIGH 7.5
CVE-2026-59936

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not ter…

Fix: 6.14.1+
Fix from $1,950 2026-07-08
Nats Server HIGH 7.5
CVE-2026-58210

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQT…

Fix: 2.12.12 / 2.14.3+
Fix from $1,950 2026-07-08
Pypdf HIGH 7.5
CVE-2026-59937

pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams…

Fix: 6.14.0+
Fix from $1,950 2026-07-08
Immutable HIGH 7.5
CVE-2026-59879

Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the…

Fix: 4.3.9 / 5.1.8+
Fix from $1,950 2026-07-08
Vllm MEDIUM 6.5
CVE-2026-55646

vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations rou…

Fix: 0.24.0+
Fix from $1,600 2026-07-06
Privileged Remote Access HIGH 7.5
CVE-2026-40140

BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsyst…

Fix: 25.3.3+
Fix from $1,950 2026-07-06
Pydantic Settings MEDIUM 5.3
CVE-2026-58203

pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files i…

Fix: 2.14.2+
Fix from $1,600 2026-07-06
Unclassified HIGH 7.7
CVE-2026-9165

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authe…

Mitigation only
Fix from $1,950 2026-07-06
Iotdb HIGH 7.5
CVE-2026-24012

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation …

Fix: 2.0.8+
Fix from $1,950 2026-07-06
Unclassified HIGH 7.5
CVE-2026-26307

Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.

Patch available
Fix from $1,950 2026-07-03
Unclassified HIGH 7.5
CVE-2026-52192

An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component

Mitigation only
Fix from $1,950 2026-07-02