Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 6.5 CVE-2026-70489 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backe… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-61387 In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, … Milo 1.1.5+ Fix from $1,9502026-08-04 MEDIUM 5.9 CVE-2026-58042 A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering … No fix yet Fix from $1,6002026-08-04 MEDIUM 6.2 CVE-2026-58045 A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnera… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67978 An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame. No fix yet Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-69249 python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invali… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67973 An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67977 An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) vi… No fix yet Fix from $1,9502026-08-03 HIGH 7.1 CVE-2026-69244 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C resp… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67976 The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Den… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-69152 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() doe… Brace Expansion 1.1.18 / 2.1.4+ Fix from $1,9502026-08-03 MEDIUM 6.3 CVE-2026-67312 axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON()… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67313 axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segm… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67318 axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent w… No fix yet Fix from $1,6002026-08-01 HIGH 7.5 CVE-2026-53505 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an uppe… No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-53504 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtr… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.5 CVE-2026-52857 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml c… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-18358 A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the inco… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-55497 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed fil… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.5 CVE-2026-10695 IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries. Db2 12.1.5+ Fix from $1,6002026-07-30 HIGH 7.5 CVE-2024-25039 IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of … Engineering Requirements Management Doors Web Access after 9.7.2.11 Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-9322 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of … Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-67437 OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_au… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.2 CVE-2026-63119 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MC… No fix yet Fix from $1,6002026-07-29 HIGH 7.1 CVE-2026-16543 Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-w… No fix yet Fix from $1,9502026-07-29 HIGH 7.1 CVE-2026-15228 Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration… No fix yet Fix from $1,9502026-07-29 HIGH 8.6 CVE-2026-58182 The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Serv… Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-65324 Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-58151 Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic … Traffic Server 9.2.15 / 10.1.4+ Fix from $1,9502026-07-29