Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Db2 HIGH 7.5
CVE-2025-36070

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 is vulnerable to a denial of service as a trap…

Fix: after 12.1.3
Fix from $1,950 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-36098

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a de…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 5.5
CVE-2025-36123

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow a local user to cause a denial of s…

Fix: after 12.1.3
Fix from $1,600 2026-01-30
Db2 MEDIUM 6.5
CVE-2025-2668

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 is vulnerable to a denial of service as the server may crash when a…

Fix: after 11.5.9
Fix from $1,600 2026-01-30
Discourse MEDIUM 6.5
CVE-2025-68934

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit craft…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Go HIGH 7.5
CVE-2025-61726

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generall…

Fix: 1.24.12 / 1.25.6+
Fix from $1,950 2026-01-28
Go MEDIUM 6.5
CVE-2025-61728

archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial…

Fix: 1.24.12 / 1.25.6+
Fix from $1,600 2026-01-28
Discourse MEDIUM 5.3
CVE-2025-68659

Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application level denial of serv…

Fix: 3.5.4 / 2025.11.2+
Fix from $1,600 2026-01-28
Unclassified HIGH 7.5
CVE-2020-36943

aSc TimeTables 2021.6.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting subject title fields…

No fix yet
Fix from $1,950 2026-01-28
Gmrtd MEDIUM 6.5
CVE-2026-24738

gmrtd is a Go library for reading Machine Readable Travel Documents (MRTDs). Prior to version 0.17.2, ReadFile accepts TLVs with lengths that can ran…

Fix: 0.17.2+
Fix from $1,600 2026-01-27
Suricata HIGH 7.5
CVE-2026-22258

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o l…

Fix: 7.0.14 / 8.0.3+
Fix from $1,950 2026-01-27
Suricata HIGH 7.5
CVE-2026-22259

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amou…

Fix: 7.0.14 / 8.0.3+
Fix from $1,950 2026-01-27
Kyverno MEDIUM 6.5
CVE-2026-23881

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumptio…

Fix: 1.15.3 / 1.16.3+
Fix from $1,600 2026-01-27
Threadx Netx Duo HIGH 7.5
CVE-2025-55102

A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of …

Fix: 6.4.5.202504+
Fix from $1,950 2026-01-27
Tapinradio HIGH 7.5
CVE-2020-36949

TapinRadio 2.13.7 contains a denial of service vulnerability in the application proxy settings that allows attackers to crash the program by overflow…

No fix yet
Fix from $1,950 2026-01-27
Unclassified MEDIUM 6.5
CVE-2020-36950

Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' pa…

No fix yet
Fix from $1,600 2026-01-27
Syncbreeze HIGH 7.5
CVE-2020-36946

SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can …

No fix yet
Fix from $1,950 2026-01-27
Unclassified MEDIUM 6.4
CVE-2025-14525

A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an …

Mitigation only
Fix from $1,600 2026-01-26
Discover MEDIUM 6.5
CVE-2026-1224

Tanium addressed an uncontrolled resource consumption vulnerability in Discover.

Fix: 4.10.134 / 4.15.130+
Fix from $1,600 2026-01-26
Unclassified HIGH 7.5
CVE-2021-47894

Managed Switch Port Mapping Tool 2.85.2 contains a denial of service vulnerability that allows attackers to crash the application by creating an over…

No fix yet
Fix from $1,950 2026-01-23
Nsauditor HIGH 7.5
CVE-2021-47895

Nsauditor 3.2.2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Event Description fiel…

No fix yet
Fix from $1,950 2026-01-23
Unclassified HIGH 7.5
CVE-2021-47893

AgataSoft PingMaster Pro 2.1 contains a denial of service vulnerability in the Trace Route feature that allows attackers to crash the application by …

No fix yet
Fix from $1,950 2026-01-23
Orjson HIGH 7.5
CVE-2025-67221

The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents.

Fix: after 3.11.4
Fix from $1,950 2026-01-22
GitLab HIGH 7.5
CVE-2026-1102

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could …

Fix: 18.6.4 / 18.7.2+
Fix from $1,950 2026-01-22
GitLab HIGH 7.5
CVE-2025-13927

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could …

Fix: 18.6.4 / 18.7.2+
Fix from $1,950 2026-01-22
Seroval HIGH 7.5
CVE-2026-24006

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serializa…

Fix: 1.4.1+
Fix from $1,950 2026-01-22
Mastodon HIGH 7.5
CVE-2026-23962

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit…

Fix: 4.3.18 / 4.4.12+
Fix from $1,950 2026-01-22
Mastodon MEDIUM 6.5
CVE-2026-23963

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce …

Fix: 4.3.18 / 4.4.12+
Fix from $1,600 2026-01-22
Seroval HIGH 7.5
CVE-2026-23957

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overridin…

Fix: 1.4.1+
Fix from $1,950 2026-01-22
Everest HIGH 7.4
CVE-2025-68136

EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects l…

Fix: 2025.10.0+
Fix from $1,950 2026-01-21