Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Consul MEDIUM 6.5
CVE-2025-11375

Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length …

Fix: 1.18.12 / 1.20.8+
Fix from $1,600 2025-10-28
Tloc100 100 Firmware HIGH 7.5
CVE-2025-59459

An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.

Fix: 7.1.1+
Fix from $1,950 2025-10-27
GitLab HIGH 7.5
CVE-2025-11447

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could …

Fix: 18.3.5 / 18.4.3+
Fix from $1,950 2025-10-27
GitLab MEDIUM 6.5
CVE-2025-11974

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could …

Fix: 18.3.5 / 18.4.3+
Fix from $1,600 2025-10-27
GitLab HIGH 7.5
CVE-2025-10497

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could…

Fix: 18.3.5 / 18.4.3+
Fix from $1,950 2025-10-27
Vault HIGH 7.5
CVE-2025-12044

Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regre…

Fix: 1.16.27 / 1.20.5+
Fix from $1,950 2025-10-23
Authlib MEDIUM 6.5
CVE-2025-62706

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFL…

Fix: 1.6.5+
Fix from $1,600 2025-10-22
Signinghub HIGH 7.5
CVE-2025-56223

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uplo…

Fix: after 8.6.8
Fix from $1,950 2025-10-20
Unclassified MEDIUM 5.3
CVE-2025-62672

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs i…

Mitigation only
Fix from $1,600 2025-10-19
Unclassified MEDIUM 6.9
CVE-2025-62666

Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch Extension allows HTTP DoS.Thi…

Mitigation only
Fix from $1,600 2025-10-18
Blu Ic2 Firmware CRITICAL 9.8
CVE-2025-11832

Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Floodin…

Fix: 1.20+
Fix from $2,300 2025-10-15
F5os C HIGH 7.5
CVE-2025-59778

When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to termi…

Fix: 1.8.2+
Fix from $1,950 2025-10-15
Big Ip Advanced Web Application Firewall MEDIUM 5.3
CVE-2025-58474

When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured w…

Fix: 17.1.2+
Fix from $1,600 2025-10-15
Big Ip Next Cloud Native Network Functions MEDIUM 6.5
CVE-2025-55670

On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microker…

Fix: after 1.9.2
Fix from $1,600 2025-10-15
Big Ip Ssl Orchestrator HIGH 7.5
CVE-2025-41430

When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versi…

Fix: 16.1.4 / 17.1.3+
Fix from $1,950 2025-10-15
Big Ip Next Cloud Native Network Functions HIGH 7.5
CVE-2025-46706

When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource u…

Fix: 16.1.6 / 17.1.2.2+
Fix from $1,950 2025-10-15
Threadx MEDIUM 5.5
CVE-2025-55079

In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't…

Fix: 6.4.3+
Fix from $1,600 2025-10-15
Unclassified HIGH 7.7
CVE-2025-9177

A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the we…

Mitigation only
Fix from $1,950 2025-10-14
Unclassified MEDIUM 5.3
CVE-2025-41704

An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the…

Mitigation only
Fix from $1,600 2025-10-14
Unclassified MEDIUM 6.9
CVE-2025-61775

Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unexpired email confirmation link…

Mitigation only
Fix from $1,600 2025-10-13
Authlib HIGH 7.5
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JW…

Fix: 1.6.5+
Fix from $1,950 2025-10-10
GitLab MEDIUM 6.5
CVE-2025-2934

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that c…

Fix: 18.2.8 / 18.3.4+
Fix from $1,600 2025-10-09
GitLab HIGH 7.5
CVE-2025-10004

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the Gi…

Fix: 18.2.8 / 18.3.4+
Fix from $1,950 2025-10-09
Pdfmake HIGH 7.5
CVE-2025-11362

Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via…

Patch available
Fix from $1,950 2025-10-07
Enterprise Analytics HIGH 7.5
CVE-2025-58582

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possi…

Mitigation only
Fix from $1,950 2025-10-06
Assimp MEDIUM 5.5
CVE-2025-11274

A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/cod…

No fix yet
Fix from $1,600 2025-10-05
Qsync Central MEDIUM 6.5
CVE-2025-52867

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can the…

Fix: 5.0.0.2+
Fix from $1,600 2025-10-03
Qsync Central MEDIUM 6.5
CVE-2025-44012

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…

Fix: 5.0.0.2+
Fix from $1,600 2025-10-03
Qsync Central MEDIUM 6.5
CVE-2025-33040

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…

Fix: 5.0.0.1+
Fix from $1,600 2025-10-03
Qsync Central MEDIUM 6.5
CVE-2025-44006

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…

Fix: 5.0.0.1+
Fix from $1,600 2025-10-03