Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 8.7 CVE-2026-46689 Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query st… Mitigation only Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-45783 libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storag… Mitigation only Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-46522 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a mis… Imagemagick 6.9.13-48 / 7.1.2-23+ Fix from $1,9502026-06-10 MEDIUM 5.3 CVE-2026-45664 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a… Imagemagick 6.9.13-47 / 7.1.2-22+ Fix from $1,6002026-06-10 MEDIUM 5.3 CVE-2026-45031 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a mis… Imagemagick 6.9.13-47 / 7.1.2-22+ Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-10143 kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-mid… Kafka Python 2.3.2+ Fix from $1,9502026-06-10 MEDIUM 5.9 CVE-2026-41711 Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort pa… Spring Data Commons 2.7.20 / 3.3.17+ Fix from $1,6002026-06-10 MEDIUM 5.9 CVE-2026-41721 Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunctio… Spring Data Commons 2.7.20 / 3.3.17+ Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-41695 Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings ar… Spring Data Commons 3.4.15 / 3.5.11.1+ Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-40988 An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of se… Spring Security 5.7.24 / 5.8.26+ Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-46374 SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.2.0, in deployments whe… Sqlfluff 4.2.0+ Fix from $1,9502026-06-09 MEDIUM 6.2 CVE-2026-47902 CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An atta… C2pa after 0.80.1 Fix from $1,6002026-06-09 MEDIUM 6.2 CVE-2026-47904 CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An atta… C2pa after 0.80.1 Fix from $1,6002026-06-09 MEDIUM 6.2 CVE-2026-47905 CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An atta… C2pa after 0.80.1 Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-34713 CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An atta… C2pa after 0.80.1 Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-36724 An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:upd… Mitigation only Fix from $1,6002026-06-09 HIGH 7.5 CVE-2025-52293 A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia… Gpac No fix yet Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-49842 FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha… Freeswitch 1.11.1+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-49160EPSS 54% Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-45591 Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. Asp.net Core 8.0.28 / 9.0.17+ Fix from $1,9502026-06-09 MEDIUM 5.1 CVE-2026-49762 Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who controls a version string to c… Patch available Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-41842 Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Fra… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-40983 In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected ver… Mitigation only Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-40984 In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected ver… Mitigation only Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-11611 A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated c… Directory Server Mitigation only Fix from $1,6002026-06-08 MEDIUM 5.3 CVE-2026-47707 Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to… Strawberry Graphql 0.315.7+ Fix from $1,6002026-06-04 MEDIUM 5.3 CVE-2026-47706 Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Ap… Strawberry Graphql 0.315.7+ Fix from $1,6002026-06-04 HIGH 7.5 CVE-2026-28318 KEVEPSS 8% SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defl… Serv U 15.5.4+ Fix from $1,9502026-06-04 MEDIUM 6.5 CVE-2026-50212 Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe de… Connect M6e 5g Firmware Mitigation only Fix from $1,6002026-06-04 HIGH 8.6 CVE-2026-46273 In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power… Linux Kernel 5.10.258 / 5.15.209+ Fix from $1,9502026-06-03