Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2025-55587 TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnera… A3002r Firmware No fix yet Fix from $1,9502025-08-18 HIGH 7.5 CVE-2025-38501 In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connec… Linux Kernel 6.1.148 / 6.6.102+ Fix from $1,9502025-08-16 MEDIUM 6.5 CVE-2025-50861 The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, which is accessible without auth… Mitigation only Fix from $1,6002025-08-14 HIGH 7.5 CVE-2025-54472 Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service vi… Brpc 1.14.1+ Fix from $1,9502025-08-14 HIGH 7.5 CVE-2025-55197 pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. … Pypdf 6.0.0+ Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-50615 A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgitest.cgi file. Attackers can tr… Wf2880 Firmware No fix yet Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-53722EPSS 18% Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network. Windows 10 1507 10.0.10240.21100 / 10.0.14393.8330+ Fix from $1,9502025-08-12 MEDIUM 5.7 CVE-2025-26472 Uncontrolled resource consumption for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authen… Mitigation only Fix from $1,6002025-08-12 MEDIUM 5.5 CVE-2025-40766 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker contai… Sinec Traffic Analyzer 3.0+ Fix from $1,6002025-08-12 MEDIUM 5.3 CVE-2025-55152 oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and … Patch available Fix from $1,6002025-08-09 HIGH 8.7 CVE-2025-54884 Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and… Patch available Fix from $1,9502025-08-06 MEDIUM 5.9 CVE-2025-8537 A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetData… Bento4 after 1.6.0-641 Fix from $1,6002025-08-05 HIGH 7.5 CVE-2025-54796 Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this f… Copyparty 1.18.9+ Fix from $1,9502025-08-02 HIGH 7.5 CVE-2025-53012 MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, ne… Materialx Patch available Fix from $1,9502025-08-01 MEDIUM 5.3 CVE-2025-54575 ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment e… Patch available Fix from $1,6002025-07-30 MEDIUM 6.9 CVE-2025-54572 The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability ex… Patch available Fix from $1,6002025-07-30 MEDIUM 5.5 CVE-2025-43235 The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause a denial-of-service. macOS 15.6+ Fix from $1,6002025-07-30 CRITICAL 9.8 CVE-2025-43193 The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app m… macOS 13.7.7 / 14.7.7+ Fix from $2,3002025-07-30 HIGH 7.5 CVE-2024-42651 NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to… Nanomq No fix yet Fix from $1,9502025-07-29 HIGH 7.5 CVE-2025-8262 A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of … Yarn after 1.22.22 Fix from $1,9502025-07-28 MEDIUM 5.4 CVE-2025-46171 vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently la… Vbulletin No fix yet Fix from $1,6002025-07-23 HIGH 7.5 CVE-2025-53538 Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.… Suricata 7.0.11+ Fix from $1,9502025-07-22 HIGH 7.5 CVE-2025-44653 In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are … Gr2200 Firmware Mitigation only Fix from $1,9502025-07-21 HIGH 7.5 CVE-2025-44650 In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can … R7000 Firmware Mitigation only Fix from $1,9502025-07-21 HIGH 7.5 CVE-2025-44651 In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimit… Tpl 430ap Firmware Mitigation only Fix from $1,9502025-07-21 MEDIUM 6.9 CVE-2025-50057 A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote attackers to deny access to se… Mitigation only Fix from $1,6002025-07-18 MEDIUM 6.5 CVE-2025-50083 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4… MySQL after 9.3.0 Fix from $1,6002025-07-15 MEDIUM 6.5 CVE-2025-50076 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.25. Easily ex… MySQL after 8.0.42 Fix from $1,6002025-07-15 MEDIUM 6.5 CVE-2025-50078 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4… MySQL after 9.3.0 Fix from $1,6002025-07-15 MEDIUM 6.5 CVE-2025-50082 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.42, 8.4… MySQL after 9.3.0 Fix from $1,6002025-07-15