Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-59941 Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared … Dompdf 3.1.6+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-59942 Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An at… Dompdf 3.1.6+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-14981 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-59932 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through … No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-59933 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through … No fix yet Fix from $1,9502026-07-28 HIGH 8.6 CVE-2026-54609 QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards REC… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-66299 Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through… Tomcat 9.0.121 / 10.1.58+ Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-66920 Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursiv… No fix yet Fix from $1,9502026-07-28 MEDIUM 6.9 CVE-2026-66913 Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially… No fix yet Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-42493 Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out ov… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2025-63913 An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and co… No fix yet Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-55685 React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests t… React Router 7.18.0+ Fix from $1,9502026-07-27 MEDIUM 5.5 CVE-2026-64724 The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia… Ipados 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-43804 This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS … Safari 26.6+ Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-43806 A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cau… macOS 26.6+ Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-43768 The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may… macOS 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-28932 A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8,… macOS 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 MEDIUM 5.3 CVE-2026-17501 A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp … No fix yet Fix from $1,6002026-07-27 HIGH 7.5 CVE-2026-66142 Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to … Neethi 3.2.3+ Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-66143 It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies… Neethi No fix yet Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-66144 Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of … Neethi 3.2.3+ Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-14257 brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-21723 The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-e… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.5 CVE-2026-38763 An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828 No fix yet Fix from $1,6002026-07-22 MEDIUM 6.6 CVE-2026-45820 fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry dec… No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-63263 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticat… Elasticsearch 8.19.19 / 9.3.8+ Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-63260 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker w… Kibana 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-63261 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authentica… Kibana 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 HIGH 7.5 CVE-2026-56819 Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Fina… Netty 4.1.136 / 4.2.16+ Fix from $1,9502026-07-21 HIGH 7.6 CVE-2026-62518 Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a… E Business Suite after 12.2.15 Fix from $1,9502026-07-21