Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 8.7 CVE-2025-58451 Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially exponential worst-case comple… Patch available Fix from $1,9502025-09-08 HIGH 7.5 CVE-2025-52288 Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function (AMF) compo… Open5gs after 2.7.5 Fix from $1,9502025-09-08 MEDIUM 5.3 CVE-2025-58369 fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, and 3.13.0-M1 through 3.13.0-M… Patch available Fix from $1,6002025-09-05 MEDIUM 6.2 CVE-2024-40664 In setupAccessibilityServices of AccessibilityFragment.java , there is a possible way to hide an enabled accessibility service due to a logic error i… Android Mitigation only Fix from $1,6002025-09-04 MEDIUM 5.5 CVE-2025-48542 In multiple functions of AccountManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to l… Android Patch available Fix from $1,6002025-09-04 MEDIUM 5.5 CVE-2025-26463 In allowPackageAccess of multiple files, resource exhaustion is possible when repeatedly adding allowed packages. This could lead to a local persiste… Android Patch available Fix from $1,6002025-09-04 MEDIUM 5.5 CVE-2025-26449 In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no… Android Patch available Fix from $1,6002025-09-04 MEDIUM 6.2 CVE-2025-26423 In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. This coul… Android Patch available Fix from $1,6002025-09-04 HIGH 7.1 CVE-2025-43772 Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not … Mitigation only Fix from $1,9502025-09-04 HIGH 7.5 CVE-2025-36892 Denial of service Android No fix yet Fix from $1,9502025-09-04 HIGH 7.5 CVE-2025-52494 Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes during conne… Ada Web Server 26.0+ Fix from $1,9502025-09-03 MEDIUM 6.3 CVE-2024-13065 Improper Enforcement of Behavioral Workflow, Uncontrolled Resource Consumption vulnerability in Akinsoft MyRezzta allows Input Data Manipulation, CAP… Mitigation only Fix from $1,6002025-09-03 HIGH 7.5 CVE-2025-57614 An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in the cached method allows an at… Rust Ffmpeg No fix yet Fix from $1,9502025-09-02 HIGH 7.5 CVE-2025-58157 gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerability when computing scalar multi… Gnark Patch available Fix from $1,9502025-08-29 MEDIUM 5.3 CVE-2025-9670 A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Perform… Mitigation only Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-29898 An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can the… Qsync Central 4.5.0.7+ Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-54995 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resou… Asterisk 18.9 / 18.26.4+ Fix from $1,6002025-08-28 MEDIUM 5.5 CVE-2024-49740 In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execu… Android No fix yet Fix from $1,6002025-08-26 HIGH 7.5 CVE-2025-55634 Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 a… Smart 2k\+ Plug In Wi Fi Video Doorbell With Chime Firmware No fix yet Fix from $1,9502025-08-22 MEDIUM 5.9 CVE-2025-9341 Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips on All (API modules), Legion … Mitigation only Fix from $1,6002025-08-22 HIGH 7.7 CVE-2025-57751 pyLoad is the free and open-source Download Manager written in pure Python. The jk parameter is received in pyLoad CNL Blueprint. Due to the lack of … Mitigation only Fix from $1,9502025-08-21 MEDIUM 6.5 CVE-2025-55521 An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial of Service (DoS) via a crafted… Akaunting after 3.1.19 Fix from $1,6002025-08-21 MEDIUM 5.5 CVE-2025-9308 A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such mani… Yarn after 1.22.22 Fix from $1,6002025-08-21 HIGH 7.5 CVE-2025-48956 vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.10.1.1, a Denial of Service (DoS) vulnerability can … Vllm 0.10.1.1+ Fix from $1,9502025-08-21 HIGH 7.5 CVE-2025-5115 In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM fra… Jetty after 12.0.21 Fix from $1,9502025-08-20 HIGH 7.5 CVE-2025-9182 Denial-of-service due to out-of-memory in the Graphics: WebRender component. This vulnerability was fixed in Firefox 142, Firefox ESR 140.2, Thunderb… Firefox 140.2.0 / 142.0+ Fix from $1,9502025-08-19 HIGH 7.5 CVE-2025-55029 Malicious scripts could bypass the popup blocker to spam new tabs, potentially resulting in denial of service attacks. This vulnerability was fixed i… Firefox 142.0+ Fix from $1,9502025-08-19 MEDIUM 6.5 CVE-2025-55028 Malicious scripts utilizing repetitive JavaScript alerts could prevent client user interaction in some scenarios and allow for denial of service atta… Firefox 142.0+ Fix from $1,6002025-08-19 HIGH 7.5 CVE-2025-55588 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability al… A3002r Firmware No fix yet Fix from $1,9502025-08-18 HIGH 7.5 CVE-2025-55586 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allo… A3002r Firmware No fix yet Fix from $1,9502025-08-18