Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2025-61600 Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerability in the IMAP protocol pars… Patch available Fix from $1,9502025-10-02 HIGH 8.8 CVE-2025-61595 MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce… Patch available Fix from $1,9502025-10-02 HIGH 7.5 CVE-2025-56572 An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter. Finance.js No fix yet Fix from $1,9502025-09-30 HIGH 7.5 CVE-2025-11149 This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception … Patch available Fix from $1,9502025-09-30 HIGH 7.5 CVE-2025-56233 Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, Openindiana has a w… Mitigation only Fix from $1,9502025-09-29 HIGH 7.5 CVE-2025-56234 AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST packets, PLC AT_NA2000 has a w… Mitigation only Fix from $1,9502025-09-29 HIGH 7.5 CVE-2024-57412 An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP packets. Mitigation only Fix from $1,9502025-09-29 HIGH 7.5 CVE-2025-55559 An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras.layers.Conv2D. Tensorflow No fix yet Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-55560 An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse() and torch.Tensor.to_dense(… Pytorch after 2.7.0 Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-57446 An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a denial of service (DoS) via a cra… Mitigation only Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-55558 A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshrink, and torch.Tensor.view-to… Pytorch after 2.7.0 Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-59830 Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &,… Rack 2.2.18+ Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-55551 An issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation. Pytorch after 2.8.0 Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-57317 apidoc-core is the core parser library to generate apidoc result following the apidoc-spec. A Prototype Pollution vulnerability in the preProcess fun… Apidoc Core after 0.15.0 Fix from $1,9502025-09-25 HIGH 7.5 CVE-2025-48392 A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to… Iotdb 2.0.5+ Fix from $1,9502025-09-24 HIGH 7.5 CVE-2025-6921 The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay … Transformers 4.53.0+ Fix from $1,9502025-09-23 HIGH 7.5 CVE-2025-57440 The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated plaintext commands for contro… Mitigation only Fix from $1,9502025-09-22 MEDIUM 5.3 CVE-2025-58767 REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations. I… Rexml 3.4.2+ Fix from $1,6002025-09-17 HIGH 7.5 CVE-2025-35432 CISA Thorium does not rate limit requests to send account verification email messages. A remote unauthenticated attacker can send unlimited messages … Thorium Patch available Fix from $1,9502025-09-17 HIGH 7.5 CVE-2025-56264 The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability. Oneblog No fix yet Fix from $1,9502025-09-16 MEDIUM 5.5 CVE-2025-43295 A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7 and iPadOS 18.7, macOS Sequoia 15.7, macOS Sonoma 1… Ipados 14.8 / 15.7+ Fix from $1,6002025-09-15 HIGH 7.5 CVE-2025-43796 Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not li… Digital Experience Platform 7.4.3.102 / 2023.Q3.5+ Fix from $1,9502025-09-12 MEDIUM 5.3 CVE-2025-59139 Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middlewar… Hono 4.9.7+ Fix from $1,6002025-09-12 MEDIUM 5.3 CVE-2025-48039 Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Ex… Patch available Fix from $1,6002025-09-11 MEDIUM 6.9 CVE-2025-48040 Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is ass… Patch available Fix from $1,6002025-09-11 HIGH 7.1 CVE-2025-48041 Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This v… Patch available Fix from $1,9502025-09-11 MEDIUM 5.3 CVE-2025-48038 Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Ex… Patch available Fix from $1,6002025-09-11 HIGH 7.4 CVE-2025-20340 A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to… Mitigation only Fix from $1,9502025-09-10 HIGH 7.5 CVE-2025-49460 Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network acce… Workplace Desktop 6.3.14 / 6.4.12+ Fix from $1,9502025-09-09 HIGH 7.5 CVE-2025-52322 An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (… Open5gs after 2.7.2 Fix from $1,9502025-09-09