Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-24485 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD f… Imagemagick 6.9.13-40 / 7.1.2-15+ Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2025-70327 TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executa… X5000r Firmware Mitigation only Fix from $2,3002026-02-23 MEDIUM 6.5 CVE-2026-26047 A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution tim… Moodle 4.5.9 / 5.0.5+ Fix from $1,6002026-02-21 HIGH 7.5 CVE-2026-25535 jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of s… Jspdf 4.2.0+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2019-25401 Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin configuration page. Remote a… No fix yet Fix from $1,9502026-02-18 MEDIUM 6.5 CVE-2026-23596 A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful … Aruba Networking Private 5g Core after 1.24.3.3 Fix from $1,6002026-02-17 MEDIUM 6.2 CVE-2025-66676 An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request. Iobit Unlocker No fix yet Fix from $1,6002026-02-13 HIGH 7.5 CVE-2026-25949 Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unau… Traefik 3.6.8+ Fix from $1,9502026-02-12 HIGH 7.5 CVE-2026-21435 webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of service in webtransport-go by … Webtransport Go 0.10.0+ Fix from $1,9502026-02-12 HIGH 7.5 CVE-2025-70886 An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission end… Halo after 2.22.4 Fix from $1,9502026-02-12 MEDIUM 5.3 CVE-2026-20676 This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS … Safari 26.3+ Fix from $1,6002026-02-11 HIGH 7.5 CVE-2026-20652 The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, ma… Safari 18.7.5 / 26.3+ Fix from $1,9502026-02-11 HIGH 7.5 CVE-2026-20650 A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visio… Ipados 26.3+ Fix from $1,9502026-02-11 MEDIUM 5.5 CVE-2026-20602 The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app … macOS 14.8.4 / 15.7.4+ Fix from $1,6002026-02-11 MEDIUM 5.7 CVE-2025-46304 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.… Ipados 14.8.4 / 15.7.4+ Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2025-62854 An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can th… File Station 5.5.6.5190+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-54149 An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-54150 An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-54151 An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-70347 An issue in mquickjs before commit 74b7e (2026-01-15) allows a local attacker to cause a denial of service via a crafted file to the get_mblock_size … Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.5 CVE-2024-54192 An issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of service via a crafted file to the tcpedit_dlt_getplugin function at src/tcpe… Patch available Fix from $1,6002026-02-10 HIGH 7.5 CVE-2026-25791 Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP boo… Sliver 1.7.0+ Fix from $1,9502026-02-09 HIGH 7.5 CVE-2026-25762 AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multi… Bodyparser 10.1.3 / 11.0.0+ Fix from $1,9502026-02-06 MEDIUM 6.5 CVE-2026-25579 Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome serv… Navidrome 0.60.0+ Fix from $1,6002026-02-04 HIGH 7.5 CVE-2025-71031 Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maximum length. As a result, an ex… Melon after 2025-01-18 Fix from $1,9502026-02-04 HIGH 7.5 CVE-2026-25140 apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or… Apko 1.1.1+ Fix from $1,9502026-02-04 MEDIUM 5.5 CVE-2026-25122 apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the … Apko 1.1.0+ Fix from $1,6002026-02-04 HIGH 7.5 CVE-2025-59439 An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and Modem 5123.… Exynos 990 Firmware Mitigation only Fix from $1,9502026-02-03 MEDIUM 5.3 CVE-2025-6208 The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption due to a resource management… Patch available Fix from $1,6002026-02-02 MEDIUM 5.7 CVE-2025-7105 A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork` to fork numerous contents r… Patch available Fix from $1,6002026-02-02