Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2025-26673 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw… Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-26652 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-26641 Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. Windows 10 1507 10.0.10240.20978 / 10.0.14393.7969+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2025-21174 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a networ… Windows Server 2012 10.0.14393.7969 / 10.0.17763.7136+ Fix from $1,9502025-04-08 HIGH 7.5 CVE-2024-52981 An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects co… Elasticsearch 7.17.24 / 8.15.1+ Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2024-52974 An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful att… Kibana 7.17.23 / 8.15.1+ Fix from $1,6002025-04-08 MEDIUM 6.5 CVE-2024-52980 A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause… Elasticsearch 8.15.1+ Fix from $1,6002025-04-08 MEDIUM 5.5 CVE-2025-29478 An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165. Fluent Bit No fix yet Fix from $1,6002025-04-07 MEDIUM 5.5 CVE-2025-29477 An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event. Fluent Bit No fix yet Fix from $1,6002025-04-04 HIGH 7.5 CVE-2024-56528 This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involv… Stream Collector 3.3.0+ Fix from $1,9502025-04-03 HIGH 7.5 CVE-2024-47212 An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can … Iglu Server 0.13.1+ Fix from $1,9502025-04-03 HIGH 7.3 CVE-2025-27829 An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may b… Mitigation only Fix from $1,9502025-04-01 CRITICAL 9.8 CVE-2025-24264 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.… Safari 2.4 / 15.4+ Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2025-24269 The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected system termi… macOS 15.4+ Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2025-24260 The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attac… macOS 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 CRITICAL 9.8 CVE-2025-24247 A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An a… macOS 13.7.5 / 14.7.5+ Fix from $2,3002025-03-31 MEDIUM 5.5 CVE-2025-24235 A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Vent… macOS 13.7.5 / 14.7.5+ Fix from $1,6002025-03-31 CRITICAL 9.8 CVE-2025-24211 This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Son… Ipados 2.4 / 13.7.5+ Fix from $2,3002025-03-31 MEDIUM 5.5 CVE-2025-24199 An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, mac… macOS 13.7.5 / 14.7.5+ Fix from $1,6002025-03-31 CRITICAL 9.8 CVE-2025-24190 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sono… Ipados 2.4 / 13.7.5+ Fix from $2,3002025-03-31 MEDIUM 6.5 CVE-2025-3016 A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImp… Assimp Patch available Fix from $1,6002025-03-31 HIGH 7.5 CVE-2025-2586 A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent e… Patch available Fix from $1,9502025-03-31 HIGH 7.5 CVE-2025-29487 An out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator ex… Libming No fix yet Fix from $1,9502025-03-27 MEDIUM 6.5 CVE-2025-29490 libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a De… Libming No fix yet Fix from $1,6002025-03-27 HIGH 7.5 CVE-2025-29484 An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator ex… Libming No fix yet Fix from $1,9502025-03-27 MEDIUM 5.3 CVE-2025-2833 A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component H… Oneblog after 2.3.9 Fix from $1,6002025-03-27 MEDIUM 6.5 CVE-2025-2820 An authenticated attacker can compromise the availability of the device via the network No fix yet Fix from $1,6002025-03-26 HIGH 7.5 CVE-2025-25374 In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external applicati… Core Flight System No fix yet Fix from $1,9502025-03-25 HIGH 7.5 CVE-2025-30160 Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (… Redlib 0.36.0+ Fix from $1,9502025-03-20 HIGH 7.5 CVE-2025-0187 A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to im… Gradio No fix yet Fix from $1,9502025-03-20