Vulnerability index

Browse CVEs

3,105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2026-9563 In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of charact… Patch available Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-54712 OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, t… Opentelemetry Instrumentation For Java 2.27.0+ Fix from $1,9502026-07-01 MEDIUM 5.0 CVE-2026-54786 Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; versions 37.0.0 through those be… Wasmtime 24.0.10 / 36.0.11+ Fix from $1,6002026-07-01 MEDIUM 5.3 CVE-2026-55594 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing de… Imagemagick 6.9.13-51 / 7.1.2-26+ Fix from $1,6002026-07-01 MEDIUM 5.5 CVE-2026-47262 containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a malic… Containerd 1.7.33 / 2.0.10+ Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-54428 Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl… Httpcomponents Core after 5.4.2 Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-49090 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated u… Elasticsearch 7.17.24 / 8.15.0+ Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-54399 Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlie… Httpcomponents Core after 5.4.2 Fix from $1,9502026-07-01 HIGH 8.2 CVE-2026-2891 The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data.… Mitigation only Fix from $1,9502026-07-01 MEDIUM 5.3 CVE-2026-57962 A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attack… Thunderbird 140.12.1 / 152.0.1+ Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-52197 An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-57204 pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerab… Pypdf 6.13.3+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-9002 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the X… Websphere Extreme Scale after 8.6.1.6 Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-57080 Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framin… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-57081 Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested li… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-50750 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4… Activemq Mitigation only Fix from $1,9502026-06-30 HIGH 7.7 CVE-2026-13149 brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecu… Patch available Fix from $1,9502026-06-30 MEDIUM 6.6 CVE-2026-45822 decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeC… Patch available Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-56018 JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) … Mitigation only Fix from $1,9502026-06-29 HIGH 7.5 CVE-2026-36478 An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll,… Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-47214 Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the H… Docling 2.94.0+ Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-30041 An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-57914 By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to d… Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-48619 A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the clien… Node.js Patch available Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-38640 A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a c… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-38637 An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted in… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-54092 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Patch available Fix from $1,6002026-06-25 MEDIUM 5.5 CVE-2026-52814 Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an unauthenticated, asymmetric Deni… Patch available Fix from $1,6002026-06-24 HIGH 7.7 CVE-2026-33235 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.5… Mitigation only Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-49851 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (app… Mitigation only Fix from $1,9502026-06-24