Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Starlette HIGH 7.5
CVE-2026-54283

Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource cons…

Fix: 1.3.1+
Fix from $1,950 2026-06-22
Protobufjs MEDIUM 5.3
CVE-2026-54270

protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message.$…

Fix: 8.5.0+
Fix from $1,600 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54273

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requ…

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54274

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket fram…

Fix: 3.14.1+
Fix from $1,950 2026-06-22
Grafana HIGH 7.5
CVE-2026-42127

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memor…

Fix: after 13.0.1
Fix from $1,950 2026-06-22
Db2 MEDIUM 6.5
CVE-2024-54178

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denia…

Fix: 5.4+
Fix from $1,600 2026-06-22
Unclassified HIGH 8.6
CVE-2025-7737

DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E10…

Mitigation only
Fix from $1,950 2026-06-19
Unclassified MEDIUM 5.3
CVE-2026-55205

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allow…

Patch available
Fix from $1,600 2026-06-18
Unclassified MEDIUM 5.3
CVE-2026-48990

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through…

No fix yet
Fix from $1,600 2026-06-17
Openshift Service Mesh HIGH 7.5
CVE-2026-47774

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulne…

Fix: 1.35.11 / 1.36.7+
Fix from $1,950 2026-06-17
Undici HIGH 7.5
CVE-2026-9675

Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A…

Fix: 8.5.0+
Fix from $1,950 2026-06-17
Undici HIGH 7.5
CVE-2026-12151

Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on th…

Fix: 6.27.0 / 7.28.0+
Fix from $1,950 2026-06-17
Ws HIGH 7.5
CVE-2026-48779

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7…

Fix: 5.2.5 / 6.2.4+
Fix from $1,950 2026-06-17
Unclassified MEDIUM 6.9
CVE-2026-27869

An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the…

Mitigation only
Fix from $1,600 2026-06-17
Unclassified CRITICAL 9.2
CVE-2026-48853

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated …

Patch available
Fix from $2,300 2026-06-15
Unclassified HIGH 8.7
CVE-2026-48854

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory …

Patch available
Fix from $1,950 2026-06-15
Mattermost Desktop MEDIUM 6.5
CVE-2026-8683

Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows …

Fix: after 6.1.5
Fix from $1,600 2026-06-15
Unclassified MEDIUM 6.5
CVE-2026-53522

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the Nezha…

Mitigation only
Fix from $1,600 2026-06-12
Netty MEDIUM 5.3
CVE-2026-50560

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTT…

Fix: 4.1.135 / 4.2.15+
Fix from $1,600 2026-06-12
Netty HIGH 7.5
CVE-2026-50011

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArra…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-12
Netty HIGH 7.5
CVE-2026-48748

Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Final and prior to version 4.2.15…

Fix: 4.2.15+
Fix from $1,950 2026-06-12
Netty HIGH 7.5
CVE-2026-46340

Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final …

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-12
Netty HIGH 7.5
CVE-2026-45416

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClient…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-12
Unclassified MEDIUM 5.3
CVE-2026-49347

Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. T…

Mitigation only
Fix from $1,600 2026-06-12
Netty HIGH 7.5
CVE-2026-44250

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-11
Netty HIGH 7.5
CVE-2026-44890

Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.…

Fix: 4.1.135 / 4.2.15+
Fix from $1,950 2026-06-11
Unclassified MEDIUM 6.0
CVE-2026-45802

FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2…

Patch available
Fix from $1,600 2026-06-11
Axios HIGH 7.5
CVE-2026-44488

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response…

Fix: 1.16.0+
Fix from $1,950 2026-06-11
GitLab HIGH 7.5
CVE-2026-7250

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un…

Fix: 18.10.8 / 18.11.5+
Fix from $1,950 2026-06-11
GitLab MEDIUM 6.5
CVE-2026-1500

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un…

Fix: 18.10.8 / 18.11.5+
Fix from $1,600 2026-06-11