Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 6.5 CVE-2026-34271 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.… Mysql Server after 9.6.0 Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-22021 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supporte… Jre Mitigation only Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-22017 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4… Mysql Server after 9.6.0 Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-22009 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4… Mysql Server after 9.6.0 Fix from $1,6002026-04-21 MEDIUM 6.0 CVE-2026-22003 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are a… Graalvm Mitigation only Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-6777 Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 HIGH 7.5 CVE-2026-6780 Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,9502026-04-21 HIGH 7.5 CVE-2026-6781 Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-39396 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downlo… Openbao 2.5.3+ Fix from $1,6002026-04-21 HIGH 7.5 CVE-2026-39320 Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular E… Signal K Server 2.25.0+ Fix from $1,9502026-04-21 MEDIUM 5.3 CVE-2026-6607 A security vulnerability has been detected in lm-sys fastchat up to 0.2.36. This issue affects the function api_generate of the component Worker API … Patch available Fix from $1,6002026-04-20 MEDIUM 5.3 CVE-2026-40347 Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `mu… Python Multipart 0.0.26+ Fix from $1,6002026-04-18 HIGH 7.5 CVE-2026-40481 monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request… Monetr 1.12.4+ Fix from $1,9502026-04-17 HIGH 7.5 CVE-2026-40303 zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCookie parses an attacker-suppli… Zrok 2.0.1+ Fix from $1,9502026-04-17 HIGH 7.5 CVE-2026-40192 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, … Pillow 12.2.0+ Fix from $1,9502026-04-15 HIGH 7.5 CVE-2026-3505 Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcp… Patch available Fix from $1,9502026-04-15 HIGH 7.5 CVE-2024-33618 Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessive amounts of disk space via n… Mitigation only Fix from $1,9502026-04-15 MEDIUM 6.5 CVE-2026-35034 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creati… Jellyfin 10.11.7+ Fix from $1,6002026-04-14 HIGH 7.5 CVE-2026-33116 Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a … .net 8.0.26 / 9.0.15+ Fix from $1,9502026-04-14 HIGH 7.5 CVE-2026-26171 Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. .net 7.5.6 / 7.6.1+ Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-2405 CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service whe… Powerchute Serial Shutdown 1.5+ Fix from $1,6002026-04-14 HIGH 7.5 CVE-2026-30998 An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of S… Ffmpeg after 8.0.1 Fix from $1,9502026-04-13 HIGH 7.5 CVE-2026-39304 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do… Activemq 5.19.4 / 6.2.4+ Fix from $1,9502026-04-10 MEDIUM 5.3 CVE-2026-5986 A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This man… Mitigation only Fix from $1,6002026-04-09 HIGH 7.5 CVE-2026-23869 A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turb… Mitigation only Fix from $1,9502026-04-08 MEDIUM 5.3 CVE-2026-34166 LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, the replace filter in LiquidJS incorrectly acco… Liquidjs 10.25.3+ Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-33459 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with … Kibana 8.19.14 / 9.2.8+ Fix from $1,6002026-04-08 MEDIUM 5.9 CVE-2026-39865 Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic … Axios 1.13.2+ Fix from $1,6002026-04-08 HIGH 7.5 CVE-2026-35406 Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection r… Aardvark Dns 1.17.1+ Fix from $1,9502026-04-07 CRITICAL 9.1 CVE-2026-34045 Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des… Podman Desktop 1.26.2+ Fix from $2,3002026-04-07