Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified MEDIUM 5.9
CVE-2026-53423

Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service …

Patch available
Fix from $1,600 2026-06-11
Vllm HIGH 7.5
CVE-2026-5497

vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the …

Fix: 0.19.0+
Fix from $1,950 2026-06-11
Imagemagick HIGH 7.5
CVE-2026-53460

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing ch…

Fix: 6.9.13-50 / 7.1.2-25+
Fix from $1,950 2026-06-10
Unclassified HIGH 7.5
CVE-2026-46673

Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsa…

Mitigation only
Fix from $1,950 2026-06-10
Unclassified HIGH 7.5
CVE-2026-46702

Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabled, russh accepted compressed…

No fix yet
Fix from $1,950 2026-06-10
Imagemagick MEDIUM 5.3
CVE-2026-45664

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a…

Fix: 6.9.13-47 / 7.1.2-22+
Fix from $1,600 2026-06-10
Imagemagick MEDIUM 5.3
CVE-2026-45031

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a mis…

Fix: 6.9.13-47 / 7.1.2-22+
Fix from $1,600 2026-06-10
Unclassified MEDIUM 5.3
CVE-2026-10740

Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of s…

Mitigation only
Fix from $1,600 2026-06-10
File Station MEDIUM 6.5
CVE-2026-24720

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a…

Fix: 5.5.6.5243+
Fix from $1,600 2026-06-10
Spring For Apache Kafka MEDIUM 6.5
CVE-2026-41726

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spr…

Fix: 2.8.12 / 2.9.14+
Fix from $1,600 2026-06-10
Spring Data Commons HIGH 7.5
CVE-2026-41716

Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion throug…

Fix: 2.7.20 / 3.3.17+
Fix from $1,950 2026-06-10
Uprof MEDIUM 5.5
CVE-2026-28237

Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability.

Fix: 5.3.518+
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.3
CVE-2026-49955

Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service ava…

Patch available
Fix from $1,600 2026-06-09
Asp.net Core HIGH 7.5
CVE-2026-45591

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.28 / 9.0.17+
Fix from $1,950 2026-06-09
Devalue HIGH 7.5
CVE-2026-42570

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to be…

Fix: 5.8.1+
Fix from $1,950 2026-06-09
Spring Framework HIGH 7.5
CVE-2026-41851

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the ev…

Fix: 5.3.49 / 6.1.28+
Fix from $1,950 2026-06-09
Spring Hateoas HIGH 7.5
CVE-2026-41007

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HAT…

Fix: 1.5.7 / 2.3.5+
Fix from $1,950 2026-06-09
Unclassified MEDIUM 5.9
CVE-2026-41710

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache.…

No fix yet
Fix from $1,600 2026-06-09
Unclassified HIGH 7.5
CVE-2026-40983

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected ver…

Mitigation only
Fix from $1,950 2026-06-09
Unclassified HIGH 7.5
CVE-2026-40984

In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected ver…

Mitigation only
Fix from $1,950 2026-06-09
Gun HIGH 7.5
CVE-2026-43973

Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded H…

Patch available
Fix from $1,950 2026-06-08
Unclassified HIGH 7.5
CVE-2026-45290

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` i…

Mitigation only
Fix from $1,950 2026-06-05
Ironic HIGH 7.5
CVE-2026-50589

In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s…

Fix: 37.0.0+
Fix from $1,950 2026-06-05
Unclassified MEDIUM 6.5
CVE-2026-36499

A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an exce…

Mitigation only
Fix from $1,600 2026-06-04
Quic Go HIGH 7.5
CVE-2026-40898

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP…

Fix: 0.59.1+
Fix from $1,950 2026-06-04
Unclassified HIGH 7.5
CVE-2025-46638

Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially…

Mitigation only
Fix from $1,950 2026-06-04
Daphne HIGH 7.5
CVE-2026-44545

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both va…

Fix: 4.2.2+
Fix from $1,950 2026-06-03
Tesla MEDIUM 5.9
CVE-2026-48597

Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.…

Patch available
Fix from $1,600 2026-06-02
React Router HIGH 7.5
CVE-2026-34077

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is…

Fix: 3.0.0 / 7.14.0+
Fix from $1,950 2026-06-02
Web Help Desk HIGH 7.5
CVE-2026-28299

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to …

Fix: 2026.2+
Fix from $1,950 2026-06-02