Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HTTP Server HIGH 7.3
CVE-2026-29168

Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache…

Fix: 2.4.67+
Fix from $1,950 2026-05-05
Unclassified HIGH 7.5
CVE-2026-42437

OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSocket path that accepts oversize…

Patch available
Fix from $1,950 2026-05-05
Unclassified HIGH 7.5
CVE-2026-7776

Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS ha…

Mitigation only
Fix from $1,950 2026-05-04
Fastify\/accepts Serializer HIGH 7.5
CVE-2026-7768

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote …

Fix: 6.0.4+
Fix from $1,950 2026-05-04
N8n HIGH 7.5
CVE-2026-42236

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accept…

Fix: 1.123.32+
Fix from $1,950 2026-05-04
Prometheus HIGH 7.5
CVE-2026-42154

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) …

Fix: 3.5.3 / 3.11.3+
Fix from $1,950 2026-05-04
Opennlp HIGH 7.5
CVE-2026-42440

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3…

Fix: 2.5.9+
Fix from $1,950 2026-05-04
Unclassified MEDIUM 5.9
CVE-2025-70071

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()

Mitigation only
Fix from $1,600 2026-05-04
Unclassified HIGH 7.5
CVE-2025-70069

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method

Mitigation only
Fix from $1,950 2026-05-04
Unclassified HIGH 8.7
CVE-2026-42786

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhau…

Patch available
Fix from $1,950 2026-05-01
Unclassified MEDIUM 6.9
CVE-2026-42788

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 fr…

Patch available
Fix from $1,600 2026-05-01
Unclassified HIGH 8.2
CVE-2026-39804

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhau…

Patch available
Fix from $1,950 2026-05-01
Prosody HIGH 7.5
CVE-2026-43507

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused b…

Fix: 0.12.6 / 13.0.5+
Fix from $1,950 2026-05-01
Db2 MEDIUM 6.5
CVE-2025-36122

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user …

Fix: after 12.1.3
Fix from $1,600 2026-04-30
Cryptpad HIGH 7.5
CVE-2025-51846

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users …

Fix: 2026.2.2+
Fix from $1,950 2026-04-30
Postgresql Jdbc Driver HIGH 7.5
CVE-2026-42198

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of servi…

Fix: 42.7.11+
Fix from $1,950 2026-04-29
Openclaw MEDIUM 6.5
CVE-2026-42420

OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attacke…

Fix: 2026.4.8+
Fix from $1,600 2026-04-28
Openclaw MEDIUM 6.5
CVE-2026-41408

OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and …

Fix: 2026.3.31+
Fix from $1,600 2026-04-28
Openclaw HIGH 7.5
CVE-2026-41399

OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. Unauthenticat…

Fix: 2026.3.28+
Fix from $1,950 2026-04-28
Openclaw HIGH 7.5
CVE-2026-41400

OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start val…

Fix: 2026.3.31+
Fix from $1,950 2026-04-28
Plug.cowboy HIGH 7.5
CVE-2026-32688

Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via ato…

Fix: 2.8.1+
Fix from $1,950 2026-04-27
Axios MEDIUM 5.3
CVE-2026-42034

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed wh…

Fix: 0.31.1 / 1.15.1+
Fix from $1,600 2026-04-24
Axios MEDIUM 5.3
CVE-2026-42036

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the …

Fix: 0.31.1 / 1.15.1+
Fix from $1,600 2026-04-24
Axios HIGH 7.5
CVE-2026-42039

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no dep…

Fix: 0.31.1 / 1.15.1+
Fix from $1,950 2026-04-24
Tempo HIGH 7.5
CVE-2026-21728

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment stra…

Fix: 2.8.4 / 2.9.2+
Fix from $1,950 2026-04-24
Basic Ftp HIGH 7.5
CVE-2026-41324

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing …

Fix: 5.3.0+
Fix from $1,950 2026-04-24
Unclassified HIGH 8.2
CVE-2026-41309

Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaus…

Patch available
Fix from $1,950 2026-04-24
Unclassified MEDIUM 5.9
CVE-2026-41173

The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.S…

Patch available
Fix from $1,600 2026-04-23
Opentelemetry MEDIUM 5.9
CVE-2026-41078

OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure wh…

Fix: 1.6.0+
Fix from $1,600 2026-04-23
Nimiq Proof Of Stake MEDIUM 5.3
CVE-2026-34062

nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_t…

Fix: 1.3.0+
Fix from $1,600 2026-04-22