Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Quarkus HIGH 7.5
CVE-2025-66560

Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerabi…

Fix: 3.20.5 / 3.27.2+
Fix from $1,950 2026-01-07
Aris MEDIUM 6.5
CVE-2025-66838

In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files…

Fix: after 10.0.23.0.3587512
Fix from $1,600 2026-01-07
Unclassified MEDIUM 5.3
CVE-2025-15474

AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth L…

Mitigation only
Fix from $1,600 2026-01-07
Unclassified HIGH 7.5
CVE-2020-36907

Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unus…

No fix yet
Fix from $1,950 2026-01-06
Aiohttp HIGH 7.5
CVE-2025-69228

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way…

Fix: 3.13.3+
Fix from $1,950 2026-01-06
Aiohttp MEDIUM 5.3
CVE-2025-69229

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result…

Fix: 3.13.3+
Fix from $1,600 2026-01-06
Aiohttp HIGH 7.5
CVE-2025-69223

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a Do…

Fix: 3.13.3+
Fix from $1,950 2026-01-05
Craft Cms CRITICAL 9.1
CVE-2025-68456

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trig…

Fix: 4.16.17 / 5.8.21+
Fix from $2,300 2026-01-05
Quts Hero MEDIUM 6.5
CVE-2025-47208

An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote…

Mitigation only
Fix from $1,600 2026-01-02
Signal K Server HIGH 7.5
CVE-2025-68272

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 all…

Fix: 2.19.0+
Fix from $1,950 2026-01-01
Unclassified HIGH 7.5
CVE-2022-50799

Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server respon…

No fix yet
Fix from $1,950 2025-12-30
Impact Firmware HIGH 7.5
CVE-2022-50695

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary h…

No fix yet
Fix from $1,950 2025-12-30
Freshrss HIGH 7.5
CVE-2025-68148

FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy mod…

Fix: 1.28.0+
Fix from $1,950 2025-12-27
Unclassified HIGH 7.5
CVE-2025-11419

A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiatin…

Mitigation only
Fix from $1,950 2025-12-23
Graphql Engine HIGH 7.5
CVE-2021-47713

Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries …

No fix yet
Fix from $1,950 2025-12-22
Tapo C200 Firmware MEDIUM 6.5
CVE-2025-14299

The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated atta…

Mitigation only
Fix from $1,600 2025-12-20
Kibana MEDIUM 6.5
CVE-2025-68389

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation …

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Elasticsearch MEDIUM 6.5
CVE-2025-68384

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allo…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Packetbeat MEDIUM 5.3
CVE-2025-68388

Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Unclassified MEDIUM 5.3
CVE-2025-14466

A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with networ…

Mitigation only
Fix from $1,600 2025-12-16
Expr HIGH 7.5
CVE-2025-68156

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `mi…

Fix: 1.17.7+
Fix from $1,950 2025-12-16
Quic Go MEDIUM 5.3
CVE-2025-64702

quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HT…

Fix: 0.57.0+
Fix from $1,600 2025-12-11
GitLab MEDIUM 6.5
CVE-2025-4097

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could…

Fix: 18.4.6 / 18.5.4+
Fix from $1,600 2025-12-11
GitLab HIGH 7.5
CVE-2025-12562

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could…

Fix: 18.4.6 / 18.5.4+
Fix from $1,950 2025-12-11
GitLab MEDIUM 6.5
CVE-2025-14157

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could h…

Fix: 18.4.6 / 18.5.4+
Fix from $1,600 2025-12-11
Xwiki HIGH 7.5
CVE-2025-66473

XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST…

Fix: 16.10.11 / 17.4.4+
Fix from $1,950 2025-12-10
Unclassified HIGH 8.7
CVE-2025-9368

A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cyc…

No fix yet
Fix from $1,950 2025-12-09
Fl Switch 2708 Pn Firmware MEDIUM 6.5
CVE-2025-41694

A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more …

Fix: 3.50+
Fix from $1,600 2025-12-09
Watsonx.data MEDIUM 6.5
CVE-2025-36140

IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation o…

Fix: 2.2.2+
Fix from $1,600 2025-12-08
Android MEDIUM 5.5
CVE-2025-48569

In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no…

No fix yet
Fix from $1,600 2025-12-08