Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-50193 jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a poten… Jackson Databind 2.14.0+ Fix from $1,9502026-06-23 HIGH 7.5 CVE-2026-55446 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request … Langflow 1.0.19+ Fix from $1,9502026-06-23 CRITICAL 9.3 CVE-2026-55450EPSS 12% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to… Langflow 1.9.1+ Fix from $2,3002026-06-23 HIGH 7.5 CVE-2025-61025 An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2026-56248 Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Lev… No fix yet Fix from $1,9502026-06-23 HIGH 7.5 CVE-2023-54365 Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard libr… Go 1.20.10 / 1.21.3+ Fix from $1,9502026-06-23 MEDIUM 5.5 CVE-2026-49461 pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to larg… Pypdf 6.12.2+ Fix from $1,6002026-06-22 HIGH 7.5 CVE-2026-53539 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParse… Python Multipart 0.0.30+ Fix from $1,9502026-06-22 MEDIUM 6.1 CVE-2026-50171 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-r… Angular 19.2.23 / 20.3.22+ Fix from $1,6002026-06-22 HIGH 7.5 CVE-2026-42127 The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memor… Grafana after 13.0.1 Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-9071 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of … Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-9320 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of … Websphere Application Server 8.5.5.30 / 9.0.5.29+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-54268 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, … Angular 20.3.25 / 21.2.17+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-49293 js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 parse hexadecimal / octal / bin… Js Toml 1.1.1+ Fix from $1,9502026-06-19 HIGH 7.5 CVE-2026-9375 urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issu… Patch available Fix from $1,9502026-06-19 MEDIUM 6.5 CVE-2026-27878 A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting … Tempo 2.8.4 / 2.9.2+ Fix from $1,6002026-06-19 HIGH 7.5 CVE-2026-48937 A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supp… Node.js Mitigation only Fix from $1,9502026-06-18 HIGH 7.5 CVE-2025-53114 CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0.0 through 7.0.18, and 8.0.0 … Patch available Fix from $1,9502026-06-18 HIGH 8.7 CVE-2025-32392 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, AutoGPT's… Mitigation only Fix from $1,9502026-06-18 HIGH 8.7 CVE-2025-32422 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `StepThro… Mitigation only Fix from $1,9502026-06-18 HIGH 8.7 CVE-2025-32424 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, Screensho… Mitigation only Fix from $1,9502026-06-18 HIGH 7.1 CVE-2025-32436 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `AddAudio… Mitigation only Fix from $1,9502026-06-18 HIGH 8.7 CVE-2025-32437 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `MediaDur… Mitigation only Fix from $1,9502026-06-18 MEDIUM 6.5 CVE-2026-44645 LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the renderLimit option can b… Patch available Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-45357 LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime i… Patch available Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-50196 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eu… Patch available Fix from $1,9502026-06-17 MEDIUM 5.3 CVE-2026-48990 joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through… No fix yet Fix from $1,6002026-06-17 MEDIUM 5.3 CVE-2026-48988 markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadr… Markdown It 14.2.0+ Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-9675 Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A… Undici 8.5.0+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-12151 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on th… Undici 6.27.0 / 7.28.0+ Fix from $1,9502026-06-17