Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-23824 Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnera… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-44167 phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RS… Patch available Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-40016 Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of … Dovecot 2.4.4 / 3.1.5+ Fix from $1,6002026-05-12 MEDIUM 6.2 CVE-2026-43653 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 1… Ipados 14.8.7 / 18.7.9+ Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-28908 A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Taho… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28872 A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26… Ipados 18.7.9 / 26.4+ Fix from $1,9502026-05-11 MEDIUM 5.3 CVE-2026-8319 A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_rel… Mitigation only Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-7790 Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding … Cowlib 2.16.1+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-31247 Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without… Mitigation only Fix from $1,9502026-05-11 HIGH 8.6 CVE-2025-10470 The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to un… Identity Server 7.0.0.121+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-8187 A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executi… Open5gs after 2.7.7 Fix from $1,9502026-05-09 MEDIUM 6.3 CVE-2026-42343 FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and … Mitigation only Fix from $1,6002026-05-08 HIGH 7.1 CVE-2026-42212 SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Op… Patch available Fix from $1,9502026-05-08 HIGH 7.5 CVE-2026-38361 Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/… Dash Uploader after 0.6.1 Fix from $1,9502026-05-08 HIGH 7.5 CVE-2024-27686 Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet d… No fix yet Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2022-26523 The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrar… Mitigation only Fix from $1,6002026-05-08 MEDIUM 5.5 CVE-2026-8124 A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. T… Gpac after 26.02.0 Fix from $1,6002026-05-08 HIGH 7.5 CVE-2025-65122 Regex Denial of Service in youtube-regex npm package through version 1.0.5. Mitigation only Fix from $1,9502026-05-07 MEDIUM 6.9 CVE-2026-32686 Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not boun… Patch available Fix from $1,6002026-05-07 MEDIUM 5.3 CVE-2026-41310 OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cach… Opentelemetry.exporter.zipkin 1.15.3+ Fix from $1,6002026-05-06 HIGH 7.5 CVE-2026-34473 Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H208N, H367N, H181A, and H196Q… Mitigation only Fix from $1,9502026-05-06 HIGH 7.5 CVE-2026-23870 A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to serv… React Server Dom Parcel after 19.2.5 Fix from $1,9502026-05-06 HIGH 7.5 CVE-2026-32936 CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter va… Coredns 1.14.3+ Fix from $1,9502026-05-05 HIGH 7.3 CVE-2026-43870 Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in… Thrift 0.23.0+ Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-42154 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) … Prometheus 3.5.3 / 3.11.3+ Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-37459 An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UP… Patch available Fix from $1,9502026-05-04 MEDIUM 5.9 CVE-2025-70071 An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray() Mitigation only Fix from $1,6002026-05-04 HIGH 7.5 CVE-2025-70069 An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method Mitigation only Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-42467 An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read_Binary_Data_Transfer_DM… Mitigation only Fix from $1,9502026-05-01 HIGH 7.5 CVE-2026-42403 Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains circular policy references (wher… Neethi 3.2.2+ Fix from $1,9502026-05-01