Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Nanazip MEDIUM 5.5
CVE-2026-42444

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem ima…

Fix: 6.0.1698.0+
Fix from $1,600 2026-05-12
Arubaos HIGH 7.5
CVE-2026-23826

A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerabilit…

Fix: 8.10.0.22 / 8.12.0.7+
Fix from $1,950 2026-05-12
Tomcat HIGH 7.5
CVE-2026-41284

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2…

Fix: 9.0.118 / 10.1.55+
Fix from $1,950 2026-05-12
Simatic Cn 4100 Firmware HIGH 7.5
CVE-2026-22925

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when sub…

Fix: 5.0+
Fix from $1,950 2026-05-12
Net\ MEDIUM 6.5
CVE-2026-42256

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.…

Fix: 0.4.24 / 0.5.14+
Fix from $1,600 2026-05-09
Argo Workflows HIGH 7.5
CVE-2026-42294

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, …

Fix: 3.7.14 / 4.0.5+
Fix from $1,950 2026-05-09
Russh HIGH 7.5
CVE-2026-42189

Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's key…

Fix: 0.23.1 / 0.60.1+
Fix from $1,950 2026-05-08
Unclassified HIGH 8.7
CVE-2026-44499

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeli…

Mitigation only
Fix from $1,950 2026-05-08
Absinthe HIGH 7.5
CVE-2026-42793

Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via atom tab…

Fix: 1.10.2+
Fix from $1,950 2026-05-08
Zebra Chain MEDIUM 5.3
CVE-2026-44500

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version…

Fix: 4.4.0 / 6.0.0+
Fix from $1,600 2026-05-08
Linux Kernel HIGH 7.8
CVE-2026-43329

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum …

Fix: 5.15.203 / 6.1.168+
Fix from $1,950 2026-05-08
Cloudstack MEDIUM 5.3
CVE-2025-69233

Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t…

Fix: 4.20.3.0 / 4.22.0.1+
Fix from $1,600 2026-05-08
Gpac MEDIUM 5.5
CVE-2026-8124

A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. T…

Fix: after 26.02.0
Fix from $1,600 2026-05-08
Enterprise Server HIGH 7.5
CVE-2026-7541

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by …

Fix: 3.16.18 / 3.17.15+
Fix from $1,950 2026-05-07
Go HIGH 7.5
CVE-2026-39820

Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

Fix: 1.25.10 / 1.26.3+
Fix from $1,950 2026-05-07
Incus MEDIUM 5.0
CVE-2026-41648

Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML f…

Fix: 7.0.0+
Fix from $1,600 2026-05-07
Unclassified HIGH 8.3
CVE-2025-14341

Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in…

Mitigation only
Fix from $1,950 2026-05-07
Monetr HIGH 7.1
CVE-2026-41644

monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) vulnerability in monetr's Lun…

Fix: 1.12.5+
Fix from $1,950 2026-05-07
Opentelemetry.exporter.onecollector MEDIUM 5.9
CVE-2026-41484

OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, whe…

Fix: after 1.15.0
Fix from $1,600 2026-05-06
Opentelemetry.exporter.zipkin MEDIUM 5.3
CVE-2026-41310

OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cach…

Fix: 1.15.3+
Fix from $1,600 2026-05-06
Opentelemetry.resources.azure MEDIUM 5.9
CVE-2026-41483

OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequest…

Fix: after 1.15.0
Fix from $1,600 2026-05-06
Vert.x MEDIUM 5.3
CVE-2026-6860

A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if…

Fix: after 5.0.11
Fix from $1,600 2026-05-06
Coredns HIGH 7.5
CVE-2026-32934

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and m…

Fix: 1.14.3+
Fix from $1,950 2026-05-05
Unclassified HIGH 8.7
CVE-2026-32689

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport…

Patch available
Fix from $1,950 2026-05-05
Unclassified HIGH 7.5
CVE-2025-66369

An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 24…

Mitigation only
Fix from $1,950 2026-05-05
HTTP Server HIGH 7.3
CVE-2026-29168

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache…

Fix: 2.4.67+
Fix from $1,950 2026-05-05
Unclassified HIGH 7.5
CVE-2026-42437

OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSocket path that accepts oversize…

Patch available
Fix from $1,950 2026-05-05
Unclassified HIGH 7.5
CVE-2026-7776

Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS ha…

Mitigation only
Fix from $1,950 2026-05-04
Fastify\/accepts Serializer HIGH 7.5
CVE-2026-7768

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote …

Fix: 6.0.4+
Fix from $1,950 2026-05-04
N8n HIGH 7.5
CVE-2026-42236

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accept…

Fix: 1.123.32+
Fix from $1,950 2026-05-04