Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-48439 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack… C2pa 0.12.1 / 0.27.6+ Fix from $4,9002026-08-11 MEDIUM 6.2 CVE-2026-48443 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.2 CVE-2026-48434 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack… C2pa 0.12.1 / 0.27.6+ Fix from $4,0002026-08-11 MEDIUM 6.9 CVE-2026-20780 Uncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of ser… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-44630 Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sen… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-18464 The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthentica… No fix yet Fix from $4,9002026-08-09 MEDIUM 5.9 CVE-2026-49343 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a … No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-52879 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a … No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-52880 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable de… No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-47249 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-54338 JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authe… No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-62295 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in … No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-62296 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no… No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-65819 gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or o… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-19113 Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API e… No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2025-63235 In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients se… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-16265 The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it disp… No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-70646 aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire reques… No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-57819 Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, … Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-64958 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-67872 An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-67864 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic compon… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-71314 Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island … No fix yet Fix from $1,9502026-08-05 MEDIUM 5.9 CVE-2026-71310 rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNEC… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-63457 A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. Integrated Lights Out 6 Firmware 1.78+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-48834 Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticate… Answer 2.0.2+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67861 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67862 open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attack… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67855 open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This all… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67856 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(S… No fix yet Fix from $1,9502026-08-04