Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified HIGH 7.5
CVE-2026-50142

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memo…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-52732

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Z…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-47628

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successf…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-74039

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to …

Fix unknown
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-73997

Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

Fix unknown
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-47683

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.1
CVE-2026-75050

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

Fix unknown
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-64868

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webho…

Fix unknown
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74878

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on …

Fix unknown
Fix from $5,750 2026-08-17
Unclassified HIGH 8.7
CVE-2026-74784

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respect…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-74786

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) ca…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.5
CVE-2026-74788

Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_righ…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-73060

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-73062

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enf…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-72888

Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores…

Fix unknown
Fix from $4,000 2026-08-16
Unclassified HIGH 7.5
CVE-2026-19474

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can…

No fix yet
Fix from $4,900 2026-08-15
Struts HIGH 7.5
CVE-2026-73635

Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localize…

Fix unknown
Fix from $4,900 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-19830

A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-72838

FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated use…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.5
CVE-2026-19617

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.5
CVE-2026-56853

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client pre…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-56859

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-56862

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a re…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-17076

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72684

A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72674

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72667

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A spec…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72659

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specia…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72651

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authe…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72653

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authe…

No fix yet
Fix from $4,000 2026-08-13