Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-19500 The Entries component in Brainstorm Force SureForms version, less than 2.1.3, does not enforce adequate limits on user-controlled form fields or subm… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-65347 The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead t… Ipados Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.5 CVE-2026-65976 Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messag… Fix unknown Fix from $4,0002026-08-17 HIGH 7.5 CVE-2026-68005 An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_req… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.9 CVE-2026-17639 Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to c… Fix unknown Fix from $4,0002026-08-17 HIGH 8.7 CVE-2026-71491 sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-o… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-59902 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessag… Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-64868 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webho… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-74785 Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through … No fix yet Fix from $4,0002026-08-16 HIGH 7.5 CVE-2026-74789 Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed ins… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-73057 stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhau… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-18549 @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit… No fix yet Fix from $4,9002026-08-15 HIGH 7.5 CVE-2026-73634 Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Content Security Policy violatio… Struts Fix unknown Fix from $4,9002026-08-15 MEDIUM 5.3 CVE-2026-19830 A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the… No fix yet Fix from $4,0002026-08-14 HIGH 7.5 CVE-2026-73633 Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO… Struts No fix yet Fix from $4,9002026-08-14 HIGH 7.5 CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-17078 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion. No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-73566 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper t… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-73568 py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxe… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-73561 Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadD… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-73559 vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vl… No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-73507 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDec… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-73556 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_outp… No fix yet Fix from $4,0002026-08-13 HIGH 8.7 CVE-2026-73413 Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/com… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-19587 Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-73228 Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py … No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-73216 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c pre… No fix yet Fix from $4,0002026-08-11 HIGH 8.2 CVE-2026-73214 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-73215 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks … No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-65785 Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network. Windows 11 24h2 10.0.26100.9106 / 10.0.26100.33222+ Fix from $4,0002026-08-11