Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Android HIGH 7.8
CVE-2025-48615

In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaustion. This could lead to local…

Mitigation only
Fix from $1,950 2025-12-08
Android MEDIUM 5.5
CVE-2025-48603

In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local deni…

Patch available
Fix from $1,600 2025-12-08
Urllib3 HIGH 7.5
CVE-2025-66418

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chai…

Fix: 2.6.0+
Fix from $1,950 2025-12-05
Unclassified HIGH 8.7
CVE-2025-12385

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Window…

Mitigation only
Fix from $1,950 2025-12-03
Dragon MEDIUM 5.5
CVE-2025-63402

An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limit…

Fix: 7.6.0+
Fix from $1,600 2025-12-03
Openvpn MEDIUM 5.5
CVE-2025-13751

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to conn…

Fix: 2.6.17+
Fix from $1,600 2025-12-03
Clipbucket MEDIUM 6.5
CVE-2025-65113

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerability in the AJAX flagging sys…

Fix: 5.5.2-164+
Fix from $1,600 2025-11-29
Suricata HIGH 7.5
CVE-2025-64334

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions fr…

Fix: 8.0.2+
Fix from $1,950 2025-11-26
GitLab MEDIUM 6.5
CVE-2025-7449

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could h…

Fix: 18.4.5 / 18.5.3+
Fix from $1,600 2025-11-26
GitLab HIGH 7.5
CVE-2025-12571

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could…

Fix: 18.4.5 / 18.5.3+
Fix from $1,950 2025-11-26
Vllm MEDIUM 6.5
CVE-2025-62426

vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/chat/completions and /tokenize…

Fix: 0.11.1+
Fix from $1,600 2025-11-21
Crypto MEDIUM 5.3
CVE-2025-58181

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause u…

Fix: 0.45.0+
Fix from $1,600 2025-11-19
Unclassified HIGH 8.3
CVE-2025-11243

Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allocation via network.

Mitigation only
Fix from $1,950 2025-11-19
Joserfc HIGH 7.5
CVE-2025-65015

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to…

Fix: 1.3.5 / 1.4.2+
Fix from $1,950 2025-11-18
Unclassified HIGH 7.5
CVE-2025-13165

EasyFlow GP developed by Digiwin has a Denial of service vulnerability, allowing unauthenticated remote attackers to send specific requests that resu…

Mitigation only
Fix from $1,950 2025-11-17
Unclassified MEDIUM 5.9
CVE-2025-59089

If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact …

Patch available
Fix from $1,600 2025-11-12
Unclassified MEDIUM 5.5
CVE-2025-12748

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL c…

Mitigation only
Fix from $1,600 2025-11-11
Spicedb MEDIUM 6.5
CVE-2025-64529

SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users who…

Fix: 1.45.2+
Fix from $1,600 2025-11-10
Unclassified HIGH 7.5
CVE-2025-64508

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli streams, such as many zeros) can b…

Patch available
Fix from $1,950 2025-11-10
Unclassified HIGH 7.5
CVE-2025-64509

Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope can cause Bugsink to spend e…

Mitigation only
Fix from $1,950 2025-11-10
Db2 MEDIUM 5.5
CVE-2025-36136

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause …

Fix: after 12.1.3
Fix from $1,600 2025-11-07
Db2 MEDIUM 6.5
CVE-2025-36008

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user …

Fix: after 12.1.3
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-53409

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-53410

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
File Station MEDIUM 6.5
CVE-2025-53413

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.5018+
Fix from $1,600 2025-11-07
Mantisbt HIGH 7.5
CVE-2025-46556

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.27.1 and below allow attackers to permanently corrupt issue activity logs b…

Fix: 2.27.2+
Fix from $1,950 2025-11-04
Go MEDIUM 5.3
CVE-2025-61724

The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response …

Fix: 1.24.8 / 1.25.2+
Fix from $1,600 2025-10-29
Go MEDIUM 5.3
CVE-2025-58185

Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.

Fix: 1.24.8 / 1.25.2+
Fix from $1,600 2025-10-29
Go HIGH 7.5
CVE-2025-61723

The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untr…

Fix: 1.24.8 / 1.25.2+
Fix from $1,950 2025-10-29
Consul MEDIUM 6.5
CVE-2025-11374

Consul and Consul Enterprise’s (“Consul”) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validati…

Fix: 1.18.12 / 1.20.8+
Fix from $1,600 2025-10-28