Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified HIGH 8.2
CVE-2026-48862

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in…

Patch available
Fix from $1,950 2026-06-02
Unclassified HIGH 8.2
CVE-2026-49754

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in…

Patch available
Fix from $1,950 2026-06-02
Ebpf Instrumentation MEDIUM 5.5
CVE-2026-45682

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcur…

Fix: 0.9.0+
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.3
CVE-2026-45554

NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-pa…

Mitigation only
Fix from $1,600 2026-06-02
Spring Cloud Function MEDIUM 6.5
CVE-2026-40990

OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud…

Fix: 3.2.16 / 4.1.10+
Fix from $1,600 2026-06-01
Openshift Container Platform MEDIUM 5.0
CVE-2026-10533

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernet…

Mitigation only
Fix from $1,600 2026-06-01
Fluss HIGH 7.5
CVE-2026-49361

Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un…

Fix: 0.9.1+
Fix from $1,950 2026-06-01
Otrs MEDIUM 5.7
CVE-2026-48187

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the…

Fix: 2026.4.1+
Fix from $1,600 2026-06-01
Unclassified HIGH 7.5
CVE-2026-46599

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image …

Mitigation only
Fix from $1,950 2026-05-29
Cpp Httplib HIGH 7.5
CVE-2026-45352

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding c…

Fix: 0.43.4+
Fix from $1,950 2026-05-29
Unclassified HIGH 8.6
CVE-2026-44697

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in B…

Mitigation only
Fix from $1,950 2026-05-29
Unclassified MEDIUM 5.4
CVE-2026-45023

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified MEDIUM 5.3
CVE-2026-45292

opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. P…

Patch available
Fix from $1,600 2026-05-28
Synapse MEDIUM 5.5
CVE-2026-45078

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of…

Fix: 1.152.1+
Fix from $1,600 2026-05-28
Pypdf MEDIUM 5.5
CVE-2026-48735

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to larg…

Fix: 6.12.1+
Fix from $1,600 2026-05-28
Volcano HIGH 7.4
CVE-2026-44247

Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size li…

Fix: 1.12.4 / 1.13.3+
Fix from $1,950 2026-05-27
GitLab MEDIUM 6.5
CVE-2026-1402

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that und…

Fix: 18.10.7 / 18.11.4+
Fix from $1,600 2026-05-27
Db2 MEDIUM 5.5
CVE-2026-6053

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partit…

Fix: after 12.1.4
Fix from $1,600 2026-05-27
Db2 HIGH 7.5
CVE-2026-1718

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transact…

Fix: after 12.1.4
Fix from $1,950 2026-05-27
Unclassified HIGH 7.5
CVE-2025-11482

An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may …

Mitigation only
Fix from $1,950 2026-05-26
Hackney HIGH 7.5
CVE-2026-47067

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts…

Fix: 4.0.1+
Fix from $1,950 2026-05-25
Unclassified MEDIUM 5.9
CVE-2026-42626

HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unaut…

Mitigation only
Fix from $1,600 2026-05-22
Moveit Automation HIGH 7.5
CVE-2026-8486

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit…

Fix: 2025.0.11 / 2025.1.7+
Fix from $1,950 2026-05-20
Moveit Automation HIGH 7.5
CVE-2026-8488

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue af…

Fix: 2025.0.11 / 2025.1.7+
Fix from $1,950 2026-05-20
Unclassified HIGH 8.2
CVE-2026-8469

Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BE…

Patch available
Fix from $1,950 2026-05-20
Bind HIGH 7.5
CVE-2026-3039

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving an…

Fix: 9.18.49 / 9.20.23+
Fix from $1,950 2026-05-20
Directory Server HIGH 7.5
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of cont…

Mitigation only
Fix from $1,950 2026-05-20
Unbound HIGH 7.5
CVE-2026-41292

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS…

Fix: 1.25.1+
Fix from $1,950 2026-05-20
Unclassified MEDIUM 5.5
CVE-2025-57798

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.14 and prior contain a Denial …

Patch available
Fix from $1,600 2026-05-19
Unclassified MEDIUM 5.8
CVE-2026-45557

Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a …

Mitigation only
Fix from $1,600 2026-05-19