Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-42304 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to … Twisted 26.4.0+ Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-33378 Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-resta… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-44248 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section i… Netty 4.1.133 / 4.2.13+ Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-42587 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxA… Netty 4.1.133 / 4.2.13+ Fix from $1,9502026-05-13 CRITICAL 9.1 CVE-2026-42579 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC… Netty 4.1.133 / 4.2.13+ Fix from $2,3002026-05-13 HIGH 7.5 CVE-2026-42583 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of… Netty 4.1.133 / 4.2.13+ Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-44456 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize… Hono 4.12.16+ Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-44296 Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow s… Patch available Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-44241 Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.… Patch available Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-42544 Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a We… Mitigation only Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-44240 basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel mul… Mitigation only Fix from $1,9502026-05-12 MEDIUM 6.2 CVE-2026-34677 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 MEDIUM 6.2 CVE-2026-34678 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-34665 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou… C2pa 0.7.1 / 0.80.1+ Fix from $1,9502026-05-12 MEDIUM 6.2 CVE-2026-34673 CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou… C2pa 0.7.1 / 0.80.1+ Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-34650EPSS 16% Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-34651 Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-34648EPSS 23% Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-34649EPSS 14% Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump… Commerce 1.3.3 / 2.4.4+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-23824 Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnera… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-44167 phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RS… Patch available Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-40016 Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of … Dovecot 2.4.4 / 3.1.5+ Fix from $1,6002026-05-12 MEDIUM 6.2 CVE-2026-43653 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 1… Ipados 14.8.7 / 18.7.9+ Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-28908 A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Taho… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28872 A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26… Ipados 18.7.9 / 26.4+ Fix from $1,9502026-05-11 MEDIUM 5.3 CVE-2026-8319 A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_rel… Mitigation only Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-7790 Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding … Cowlib 2.16.1+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-31247 Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without… Mitigation only Fix from $1,9502026-05-11 HIGH 8.6 CVE-2025-10470 The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to un… Identity Server 7.0.0.121+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-8187 A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executi… Open5gs after 2.7.7 Fix from $1,9502026-05-09