Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 6.5 CVE-2025-46392 Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.… Commons Configuration 2.0+ Fix from $1,6002025-05-09 HIGH 7.5 CVE-2025-1948 In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_… Jetty 12.0.17+ Fix from $1,9502025-05-08 HIGH 7.5 CVE-2025-46727 Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/… Rack 2.2.14 / 3.0.16+ Fix from $1,9502025-05-07 HIGH 8.6 CVE-2025-20162 A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interf… Ios Xe Mitigation only Fix from $1,9502025-05-07 MEDIUM 5.5 CVE-2025-46593 Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availabili… Harmonyos No fix yet Fix from $1,6002025-05-06 HIGH 7.5 CVE-2025-46728 cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits o… Cpp Httplib 0.20.1+ Fix from $1,9502025-05-06 MEDIUM 6.5 CVE-2025-43915 In Linkerd edge releases before edge-25.2.1, and Buoyant Enterprise for Linkerd releases 2.13.0–2.13.7, 2.14.0–2.14.10, 2.15.0–2.15.7, 2.16.0–2.16.4,… Linkerd 2.16.5 / 2.17.2+ Fix from $1,6002025-05-05 MEDIUM 5.5 CVE-2025-23246 NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to consume unco… Mitigation only Fix from $1,6002025-05-01 HIGH 7.5 CVE-2024-52979 Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial … Elasticsearch 7.17.25 / 8.16.0+ Fix from $1,9502025-05-01 MEDIUM 6.5 CVE-2025-43857 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there i… Net\ 0.2.5 / 0.3.9+ Fix from $1,6002025-04-28 MEDIUM 5.3 CVE-2025-32472 The multiScan and picoScan are vulnerable to a denial-of-service (DoS) attack. A remote attacker can exploit this vulnerability by conducting a Slowl… Mitigation only Fix from $1,6002025-04-28 HIGH 7.5 CVE-2025-3986 A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\cor… Central Authentication Service Mitigation only Fix from $1,9502025-04-27 HIGH 7.5 CVE-2025-46580 There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of busines… Zxcloud Goldendb 6.1.03.11+ Fix from $1,9502025-04-27 MEDIUM 5.7 CVE-2025-2811 A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint,… Mitigation only Fix from $1,6002025-04-26 MEDIUM 5.5 CVE-2025-27087 A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack. No fix yet Fix from $1,6002025-04-22 HIGH 7.1 CVE-2025-30158 NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post ifram… Nameless 2.2.0+ Fix from $1,9502025-04-18 HIGH 7.1 CVE-2025-31118 NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topi… Nameless 2.2.0+ Fix from $1,9502025-04-18 MEDIUM 6.7 CVE-2025-30725 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.1.6. Diff… Vm Virtualbox Patch available Fix from $1,6002025-04-15 HIGH 7.5 CVE-2025-30730 Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected ar… Application Object Library after 12.2.14 Fix from $1,9502025-04-15 MEDIUM 6.5 CVE-2025-21577 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 an… Mysql Server after 9.2.0 Fix from $1,6002025-04-15 MEDIUM 6.5 CVE-2025-21574 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-… Mysql Cluster after 9.2.0 Fix from $1,6002025-04-15 MEDIUM 6.5 CVE-2025-21575 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-… Mysql Cluster after 9.2.0 Fix from $1,6002025-04-15 MEDIUM 6.4 CVE-2023-42983 Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed w… macOS 14.0+ Fix from $1,6002025-04-11 MEDIUM 6.8 CVE-2025-27081 A potential security vulnerability in HPE NonStop OSM Service Connection Suite could potentially be exploited to allow a local Denial of Service. No fix yet Fix from $1,6002025-04-10 HIGH 7.5 CVE-2025-27485 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27486 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27473 Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27469 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw… Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-27470 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-26680 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08