Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 5.5 CVE-2025-13466 body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large numbers of parameters. An atta… Mitigation only Fix from $1,6002025-11-24 HIGH 7.5 CVE-2025-60638 An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Nnssf_NSSAIAva… Free5gc No fix yet Fix from $1,9502025-11-24 HIGH 8.7 CVE-2025-65947 thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resource leaks when querying thread… Patch available Fix from $1,9502025-11-21 MEDIUM 6.5 CVE-2025-55128 HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An att… Revive Adserver 6.0.3+ Fix from $1,6002025-11-20 HIGH 7.5 CVE-2025-37161 A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of servic… Arubaos 10.7.2.0+ Fix from $1,9502025-11-18 HIGH 7.5 CVE-2025-55796 The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation… Openml.org after 2.0.20241110 Fix from $1,9502025-11-18 HIGH 7.5 CVE-2025-6599 An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C0 and earlier could allow an … Lte3301 Plus Firmware after 5.00 Fix from $1,9502025-11-18 MEDIUM 6.5 CVE-2025-11681 Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user… M Files Server 25.2.14524.13 / 25.8.15085.17+ Fix from $1,6002025-11-17 HIGH 8.7 CVE-2021-4465 ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial… No fix yet Fix from $1,9502025-11-14 HIGH 8.7 CVE-2021-4467 Positive Technologies MaxPatrol 8 and XSpider contain a remote denial-of-service vulnerability in the client communication service on TCP port 2002. … Mitigation only Fix from $1,9502025-11-14 HIGH 8.7 CVE-2023-7326 The Epson Stylus SX510W embedded web management service fails to properly handle consecutive ampersand characters in query parameters when accessing … No fix yet Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-63811 An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encrypt… Jose2go 1.7.0+ Fix from $1,9502025-11-12 MEDIUM 5.5 CVE-2025-27249 Uncontrolled resource consumption for some Gaudi software before version 1.21.0 within Ring 3: User Applications may allow a denial of service. Syste… Mitigation only Fix from $1,6002025-11-11 HIGH 7.5 CVE-2025-63288 In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service. Open5gs Patch available Fix from $1,9502025-11-10 HIGH 7.5 CVE-2025-63560 An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via … E3 Firmware No fix yet Fix from $1,9502025-11-06 MEDIUM 5.5 CVE-2025-60753 An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s subst… Libarchive after 3.8.1 Fix from $1,6002025-11-05 HIGH 7.5 CVE-2025-49494 An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, 1480, 9110, Modem 5123. Misha… Modem 5123 Firmware Mitigation only Fix from $1,9502025-11-04 HIGH 7.5 CVE-2025-43462 The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, w… Ipados 26.1+ Fix from $1,9502025-11-04 HIGH 7.5 CVE-2025-63561 Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HT… Vacation Rental Management Platform 1.0.2+ Fix from $1,9502025-10-31 MEDIUM 5.5 CVE-2025-6075 If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables. Python 3.9.0 / 3.13.11+ Fix from $1,6002025-10-31 CRITICAL 9.2 CVE-2025-64388 Denial of service of the web server through specific requests to this protocol No fix yet Fix from $2,3002025-10-31 HIGH 7.5 CVE-2025-30188 Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to ope… Mitigation only Fix from $1,9502025-10-31 HIGH 7.5 CVE-2025-6176 Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protect… Mitigation only Fix from $1,9502025-10-31 HIGH 7.5 CVE-2025-8849 LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key… Librechat Patch available Fix from $1,9502025-10-31 MEDIUM 6.5 CVE-2025-5342 Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module. Manageengine Exchange Reporter Plus 5.7+ Fix from $1,6002025-10-30 HIGH 8.2 CVE-2025-10932 Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Transfer: from 2025.0.0 before 202… Mitigation only Fix from $1,9502025-10-29 HIGH 7.5 CVE-2025-54604 Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2). Bitcoin Core 30.0+ Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-54605 Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2). Bitcoin Core 30.0+ Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-60349 An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver.… Mitigation only Fix from $1,9502025-10-28 MEDIUM 5.5 CVE-2025-61155 The GameDriverX64.sys kernel-mode anti-cheat driver (v7.23.4.7 and earlier) contains an access control vulnerability in one of its IOCTL handlers. A … Mitigation only Fix from $1,6002025-10-28