Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-59886 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float u… Pyasn1 0.6.4+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-59200 Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize se… Pillow 12.3.0+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-59884 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating … Pyasn1 0.6.4+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-59885 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in qua… Pyasn1 0.6.4+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2026-50653 Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. .net Framework No fix yet Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-49799 Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a … Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-12523 Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/… Quiche 0.29.3+ Fix from $1,9502026-07-14 HIGH 7.5 CVE-2024-7708 For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Cont… Jetty 10.0.23 / 11.0.23+ Fix from $1,9502026-07-14 HIGH 8.3 CVE-2026-58486 HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bo… Patch available Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-51539 A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout… Mitigation only Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-59161 Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows … Excelize 2.11.0+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-39244 adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js lin… No fix yet Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-8609 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually e… Grafana 11.6.15 / 12.2.9+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-33382 Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send ver… Grafana 11.6.15 / 12.2.9+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-40007 Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap re… Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-51600 Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). … Mitigation only Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-15308 The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processi… Python 3.15.0+ Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-54772 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote att… Patch available Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-51535 In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop. Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59936 pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a not ter… Pypdf 6.14.1+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-58210 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQT… Nats Server 2.12.12 / 2.14.3+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59937 pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malformed cross-reference streams… Pypdf 6.14.0+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59879 Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the… Immutable 4.3.9 / 5.1.8+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-55646 vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations rou… Vllm 0.24.0+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-40140 BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsyst… Privileged Remote Access 25.3.3+ Fix from $1,9502026-07-06 MEDIUM 5.3 CVE-2026-58203 pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files i… Pydantic Settings 2.14.2+ Fix from $1,6002026-07-06 HIGH 7.7 CVE-2026-9165 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authe… Mitigation only Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-24012 Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation … Iotdb 2.0.8+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-26307 Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources. Patch available Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-52192 An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component Mitigation only Fix from $1,9502026-07-02