Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
GitLab MEDIUM 6.5
CVE-2025-3922

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that co…

Fix: 18.9.6 / 18.10.4+
Fix from $1,600 2026-04-22
GitLab MEDIUM 6.5
CVE-2025-6016

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that cou…

Fix: 18.9.6 / 18.10.4+
Fix from $1,600 2026-04-22
GitLab MEDIUM 6.5
CVE-2026-1660

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that un…

Fix: 18.9.6 / 18.10.4+
Fix from $1,600 2026-04-22
GitLab MEDIUM 6.5
CVE-2025-0186

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that co…

Fix: 18.9.6 / 18.10.4+
Fix from $1,600 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-33254

An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial o…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-33594

A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accu…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-33595

A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources wer…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Recursor HIGH 7.5
CVE-2026-33256

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…

Fix: 5.2.9 / 5.3.6+
Fix from $1,950 2026-04-22
Authoritative HIGH 7.5
CVE-2026-33257

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Recursor HIGH 7.5
CVE-2026-33258

By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.

Fix: 5.2.9 / 5.3.6+
Fix from $1,950 2026-04-22
Authoritative HIGH 7.5
CVE-2026-33260

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Zebra Network HIGH 7.5
CVE-2026-40881

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 mess…

Fix: 4.3.1 / 5.0.1+
Fix from $1,950 2026-04-21
Image MEDIUM 6.1
CVE-2026-33812

Parsing a malicious font file can cause excessive memory allocation.

Fix: 0.39.0+
Fix from $1,600 2026-04-21
Next Ai Draw.io MEDIUM 5.5
CVE-2026-40608

Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contai…

Fix: 0.4.15+
Fix from $1,600 2026-04-21
Freescout CRITICAL 9.8
CVE-2026-40498

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system …

Fix: 1.8.213+
Fix from $2,300 2026-04-21
Openbao MEDIUM 6.5
CVE-2026-39396

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downlo…

Fix: 2.5.3+
Fix from $1,600 2026-04-21
Vault HIGH 7.5
CVE-2026-5807

Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rek…

Fix: 2.0.0+
Fix from $1,950 2026-04-17
Unclassified HIGH 8.7
CVE-2026-39313

mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in the H…

Patch available
Fix from $1,950 2026-04-16
Unclassified MEDIUM 6.5
CVE-2026-35469

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate att…

Mitigation only
Fix from $1,600 2026-04-16
Pillow HIGH 7.5
CVE-2026-40192

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, …

Fix: 12.2.0+
Fix from $1,950 2026-04-15
Unclassified HIGH 7.5
CVE-2026-3505

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcp…

Patch available
Fix from $1,950 2026-04-15
Xwiki HIGH 8.2
CVE-2026-40104

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc…

Fix: 16.10.16 / 17.4.8+
Fix from $1,950 2026-04-15
Unclassified CRITICAL 9.8
CVE-2026-31283

In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Ema…

Mitigation only
Fix from $2,300 2026-04-13
Varnish Enterprise HIGH 7.5
CVE-2026-40395

Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() functi…

Fix: after 6.0.15
Fix from $1,950 2026-04-12
Kit HIGH 7.5
CVE-2026-40073

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, reque…

Fix: 2.57.1+
Fix from $1,950 2026-04-10
Vikunja HIGH 7.1
CVE-2026-35602

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size fi…

Fix: 2.3.0+
Fix from $1,950 2026-04-10
Activemq HIGH 7.5
CVE-2026-39304

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do…

Fix: 5.19.4 / 6.2.4+
Fix from $1,950 2026-04-10
Praisonai HIGH 7.5
CVE-2026-40115

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into …

Fix: 4.5.128+
Fix from $1,950 2026-04-09
Praisonai HIGH 7.5
CVE-2026-40116

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from a…

Fix: 4.5.128+
Fix from $1,950 2026-04-09
Openclaw MEDIUM 5.3
CVE-2026-35633

OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger …

Fix: 2026.3.22+
Fix from $1,600 2026-04-09