Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified HIGH 7.5
CVE-2026-33232

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6…

Mitigation only
Fix from $1,950 2026-05-19
Mattermost Server MEDIUM 6.5
CVE-2026-2325

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpo…

Fix: 10.11.14 / 11.4.4+
Fix from $1,600 2026-05-18
Unclassified HIGH 7.5
CVE-2021-47959

WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by send…

No fix yet
Fix from $1,950 2026-05-15
Unclassified MEDIUM 6.9
CVE-2026-44679

Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly tri…

Mitigation only
Fix from $1,600 2026-05-14
Wasmtime HIGH 7.5
CVE-2026-44216

Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained check…

Fix: 36.0.8 / 43.0.2+
Fix from $1,950 2026-05-14
Unclassified HIGH 8.2
CVE-2026-8468

Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in…

Patch available
Fix from $1,950 2026-05-14
GitLab MEDIUM 6.5
CVE-2026-8280

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou…

Fix: 18.9.7 / 18.10.6+
Fix from $1,600 2026-05-14
GitLab HIGH 7.5
CVE-2026-1659

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou…

Fix: 18.9.7 / 18.10.6+
Fix from $1,950 2026-05-14
GitLab HIGH 7.5
CVE-2025-14870

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that co…

Fix: 18.9.7 / 18.10.6+
Fix from $1,950 2026-05-14
Unclassified HIGH 7.5
CVE-2026-42561

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart par…

No fix yet
Fix from $1,950 2026-05-13
Grafana MEDIUM 6.5
CVE-2026-28383

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authentic…

Fix: 11.6.14 / 12.2.8+
Fix from $1,600 2026-05-13
Grafana MEDIUM 6.5
CVE-2026-28376

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leadin…

Fix: 11.6.14 / 12.2.8+
Fix from $1,600 2026-05-13
Unclassified HIGH 8.2
CVE-2026-8466

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in …

Patch available
Fix from $1,950 2026-05-13
Netty HIGH 7.5
CVE-2026-44248

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section i…

Fix: 4.1.133 / 4.2.13+
Fix from $1,950 2026-05-13
Netty HIGH 7.5
CVE-2026-42587

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxA…

Fix: 4.1.133 / 4.2.13+
Fix from $1,950 2026-05-13
Netty HIGH 7.5
CVE-2026-42582

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of i…

Fix: 4.2.13+
Fix from $1,950 2026-05-13
Netty HIGH 7.5
CVE-2026-42583

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of…

Fix: 4.1.133 / 4.2.13+
Fix from $1,950 2026-05-13
Next.js HIGH 7.5
CVE-2026-44579

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering th…

Fix: 15.5.16 / 16.2.5+
Fix from $1,950 2026-05-13
Vm2 HIGH 7.5
CVE-2026-44004

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory direc…

Fix: 3.11.0+
Fix from $1,950 2026-05-13
Next.js MEDIUM 5.9
CVE-2026-44577

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the d…

Fix: 15.5.16 / 16.2.5+
Fix from $1,600 2026-05-13
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2026-41227

On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the T…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-40629

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  No…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Big Ip Access Policy Manager HIGH 7.5
CVE-2026-40423

When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: So…

Fix: after 17.5.1
Fix from $1,950 2026-05-13
Autogpt Platform MEDIUM 5.5
CVE-2025-32425

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. In A…

Fix: 0.6.32+
Fix from $1,600 2026-05-13
Bandit HIGH 7.5
CVE-2026-39803

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhau…

Fix: 1.11.1+
Fix from $1,950 2026-05-13
Unclassified MEDIUM 5.1
CVE-2026-44931

The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-serv…

Mitigation only
Fix from $1,600 2026-05-13
MongoDB MEDIUM 6.5
CVE-2026-8202

Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user w…

Fix: 7.0.34 / 8.0.23+
Fix from $1,600 2026-05-13
Phpspreadsheet HIGH 7.5
CVE-2026-40863

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML …

Fix: 1.30.4 / 2.1.16+
Fix from $1,950 2026-05-12
Phpspreadsheet HIGH 7.5
CVE-2026-40902

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's …

Fix: 1.30.4 / 2.1.16+
Fix from $1,950 2026-05-12
Unclassified HIGH 7.5
CVE-2026-44240

basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel mul…

Mitigation only
Fix from $1,950 2026-05-12