Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 6.5 CVE-2025-30753 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4… Weblogic Server Patch available Fix from $1,6002025-07-15 MEDIUM 6.5 CVE-2025-53893 File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. I… Filebrowser No fix yet Fix from $1,6002025-07-15 MEDIUM 5.6 CVE-2025-48795 Apache CXF stores large stream based messages as temporary files on the local filesystem. A bug was introduced which means that the entire temporary … Cxf Mitigation only Fix from $1,6002025-07-15 HIGH 7.5 CVE-2025-24294 The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain… Mitigation only Fix from $1,9502025-07-12 MEDIUM 5.4 CVE-2025-53636 Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs c… Patch available Fix from $1,6002025-07-11 HIGH 7.5 CVE-2025-53506 Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the … Tomcat after 11.0.8 Fix from $1,9502025-07-10 CRITICAL 9.1 CVE-2025-53371 DiscordNotifications is an extension for MediaWiki that sends notifications of actions in your Wiki to a Discord channel. DiscordNotifications allows… Patch available Fix from $2,3002025-07-10 HIGH 7.5 CVE-2025-53645 Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a denial of service condition due … Mitigation only Fix from $1,9502025-07-09 MEDIUM 5.7 CVE-2025-49722 Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,6002025-07-08 HIGH 7.5 CVE-2025-49716 Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network. Windows Server 2008 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 7.5 CVE-2025-6714 MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when … MongoDB 6.0.23 / 7.0.20+ Fix from $1,9502025-07-07 MEDIUM 6.5 CVE-2025-6712 MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to ineffic… MongoDB 8.0.10+ Fix from $1,6002025-07-07 HIGH 7.5 CVE-2025-7074 A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the f… Hyper after 3.4.1 Fix from $1,9502025-07-05 HIGH 8.8 CVE-2025-7070 A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functio… Q9 Firmware after 2025-06-24 Fix from $1,9502025-07-04 HIGH 7.5 CVE-2025-53481 Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Allocation.This issue affects M… Mitigation only Fix from $1,9502025-07-04 HIGH 8.2 CVE-2025-6297 It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i… Dpkg 1.22.21+ Fix from $1,9502025-07-01 MEDIUM 6.5 CVE-2025-44559 An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a Denial of Serv… No fix yet Fix from $1,6002025-06-27 HIGH 7.5 CVE-2025-52887 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http headers fields are passed in, the… Cpp Httplib Patch available Fix from $1,9502025-06-26 MEDIUM 5.7 CVE-2024-57708 An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign co… Mitigation only Fix from $1,6002025-06-25 HIGH 7.5 CVE-2025-44531 An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing pub… Rtl8762e Software Development Kit No fix yet Fix from $1,9502025-06-24 HIGH 7.5 CVE-2025-44528 An issue in Texas Instruments LP-CC2652RB SimpleLink CC13XX CC26XX SDK 7.41.00.17 allows attackers to cause a Denial of Service (DoS) via sending a c… No fix yet Fix from $1,9502025-06-23 MEDIUM 5.3 CVE-2025-6493 A weakness has been identified in CodeMirror up to 5.65.20. Affected is an unknown function of the file mode/markdown/markdown.js of the component Ma… Mitigation only Fix from $1,6002025-06-22 MEDIUM 5.3 CVE-2025-6492 A vulnerability has been found in MarkText up to 0.17.1 and classified as problematic. Affected by this vulnerability is the function getRecommendTit… Patch available Fix from $1,6002025-06-22 HIGH 7.5 CVE-2025-6365 A vulnerability was found in HobbesOSR Kitten up to c4f8b7c3158983d1020af432be1b417b28686736 and classified as critical. Affected by this issue is th… Kitten after 2023-05-18 Fix from $1,9502025-06-20 HIGH 7.5 CVE-2025-44203 In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database … Hoteldruid Mitigation only Fix from $1,9502025-06-20 HIGH 7.5 CVE-2025-49763 ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. … Traffic Server 9.2.11 / 10.0.6+ Fix from $1,9502025-06-19 HIGH 7.5 CVE-2025-3526 SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 25, and older unsupported vers… Digital Experience Platform after 7.4.3.21 Fix from $1,9502025-06-16 HIGH 7.5 CVE-2025-3602 Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA through update 35, and 7.2 fix p… Digital Experience Platform after 2023.q3.2 Fix from $1,9502025-06-16 MEDIUM 5.6 CVE-2025-22242 Worker process denial of service through file read operation. .A vulnerability exists in the Master's “pub_ret” method which is exposed to all minion… Mitigation only Fix from $1,6002025-06-13 HIGH 7.5 CVE-2025-33068 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.8148 / 10.0.17763.7434+ Fix from $1,9502025-06-10