Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified HIGH 7.5
CVE-2026-9563

In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of charact…

Patch available
Fix from $1,950 2026-07-02
Opentelemetry Instrumentation For Java HIGH 7.5
CVE-2026-54712

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, t…

Fix: 2.27.0+
Fix from $1,950 2026-07-01
Wasmtime MEDIUM 5.0
CVE-2026-54786

Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; versions 37.0.0 through those be…

Fix: 24.0.10 / 36.0.11+
Fix from $1,600 2026-07-01
Imagemagick MEDIUM 5.3
CVE-2026-55594

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing de…

Fix: 6.9.13-51 / 7.1.2-26+
Fix from $1,600 2026-07-01
Containerd MEDIUM 5.5
CVE-2026-47262

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a malic…

Fix: 1.7.33 / 2.0.10+
Fix from $1,600 2026-07-01
Httpcomponents Core HIGH 7.5
CVE-2026-54428

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl…

Fix: after 5.4.2
Fix from $1,950 2026-07-01
Elasticsearch MEDIUM 6.5
CVE-2026-49090

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated u…

Fix: 7.17.24 / 8.15.0+
Fix from $1,600 2026-07-01
Httpcomponents Core HIGH 7.5
CVE-2026-54399

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlie…

Fix: after 5.4.2
Fix from $1,950 2026-07-01
Unclassified HIGH 8.2
CVE-2026-2891

The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data.…

Mitigation only
Fix from $1,950 2026-07-01
Thunderbird MEDIUM 5.3
CVE-2026-57962

A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attack…

Fix: 140.12.1 / 152.0.1+
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-52197

An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component

Mitigation only
Fix from $1,950 2026-06-30
Pypdf MEDIUM 6.5
CVE-2026-57204

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerab…

Fix: 6.13.3+
Fix from $1,600 2026-06-30
Websphere Extreme Scale MEDIUM 6.5
CVE-2026-9002

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the X…

Fix: after 8.6.1.6
Fix from $1,600 2026-06-30
Unclassified HIGH 7.5
CVE-2026-57080

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framin…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 7.5
CVE-2026-57081

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested li…

Mitigation only
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-50750

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 7.7
CVE-2026-13149

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecu…

Patch available
Fix from $1,950 2026-06-30
Unclassified MEDIUM 6.6
CVE-2026-45822

decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeC…

Patch available
Fix from $1,600 2026-06-30
Unclassified HIGH 7.5
CVE-2026-56018

JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) …

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.5
CVE-2026-36478

An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll,…

Mitigation only
Fix from $1,950 2026-06-26
Docling HIGH 7.1
CVE-2026-47214

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the H…

Fix: 2.94.0+
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-30041

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57914

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to d…

Mitigation only
Fix from $1,600 2026-06-26
Node.js HIGH 7.5
CVE-2026-48619

A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the clien…

Patch available
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-38640

A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a c…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-38637

An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted in…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.5
CVE-2026-54092

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Patch available
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.5
CVE-2026-52814

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an unauthenticated, asymmetric Deni…

Patch available
Fix from $1,600 2026-06-24
Unclassified HIGH 7.7
CVE-2026-33235

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.5…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.5
CVE-2026-49851

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (app…

Mitigation only
Fix from $1,950 2026-06-24