Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Qsync Central MEDIUM 6.5
CVE-2025-44007

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…

Fix: 5.0.0.1+
Fix from $1,600 2025-10-03
Qsync Central MEDIUM 6.5
CVE-2025-33039

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…

Fix: 5.0.0.1+
Fix from $1,600 2025-10-03
Unclassified HIGH 8.8
CVE-2025-61595

MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce…

Patch available
Fix from $1,950 2025-10-02
GitLab HIGH 7.5
CVE-2025-8014

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior …

Fix: 18.2.7 / 18.3.3+
Fix from $1,950 2025-09-27
GitLab HIGH 7.5
CVE-2025-11042

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that all…

Fix: 18.2.7 / 18.3.3+
Fix from $1,950 2025-09-26
GitLab MEDIUM 6.5
CVE-2025-10867

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could ha…

Fix: 18.2.7 / 18.3.3+
Fix from $1,600 2025-09-26
GitLab HIGH 7.5
CVE-2025-10858

An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that allows unauthenticated …

Fix: 18.2.7 / 18.3.3+
Fix from $1,950 2025-09-26
Rack HIGH 7.5
CVE-2025-59830

Rack is a modular Ruby web server interface. Prior to version 2.2.18, Rack::QueryParser enforces its params_limit only for parameters separated by &,…

Fix: 2.2.18+
Fix from $1,950 2025-09-25
Unclassified MEDIUM 5.5
CVE-2025-59418

BunnyPad is a note taking software. Prior to version 11.0.27000.0915, opening files greater than or equal to 20MB causes buffer overflow to occur. Th…

Patch available
Fix from $1,600 2025-09-22
Unclassified MEDIUM 6.9
CVE-2025-8396

Insufficiently specific bounds checking on authorization header could lead to denial of service in the Temporal server on all platforms due to excess…

Mitigation only
Fix from $1,600 2025-09-15
Libexpat HIGH 7.5
CVE-2025-59375

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

Fix: 2.7.2+
Fix from $1,950 2025-09-15
Powervm Hypervisor MEDIUM 5.1
CVE-2025-36035

IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to…

Mitigation only
Fix from $1,600 2025-09-14
Hono MEDIUM 5.3
CVE-2025-59139

Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middlewar…

Fix: 4.9.7+
Fix from $1,600 2025-09-12
GitLab MEDIUM 6.5
CVE-2025-7337

An issue has been discovered in GitLab CE/EE affecting all versions from 7.8 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could hav…

Fix: 18.1.6 / 18.2.6+
Fix from $1,600 2025-09-12
GitLab MEDIUM 6.5
CVE-2025-1250

An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could ha…

Fix: 18.1.6 / 18.2.6+
Fix from $1,600 2025-09-12
Axios HIGH 7.5
CVE-2025-58754

Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs …

Fix: 0.30.2 / 1.12.0+
Fix from $1,950 2025-09-12
Unclassified MEDIUM 5.3
CVE-2025-48039

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Ex…

Patch available
Fix from $1,600 2025-09-11
Unclassified MEDIUM 6.9
CVE-2025-48040

Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is ass…

Patch available
Fix from $1,600 2025-09-11
Unclassified HIGH 7.1
CVE-2025-48041

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This v…

Patch available
Fix from $1,950 2025-09-11
Unclassified MEDIUM 5.3
CVE-2025-48038

Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Ex…

Patch available
Fix from $1,600 2025-09-11
Security Verify Information Queue MEDIUM 6.5
CVE-2024-45669

IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handl…

Fix: 10.0.11+
Fix from $1,600 2025-09-10
Unclassified HIGH 7.1
CVE-2025-59045

Stalwart is a mail and collaboration server. Starting in version 0.12.0 and prior to version 0.13.3, a memory exhaustion vulnerability exists in Stal…

Patch available
Fix from $1,950 2025-09-10
Xgrammar HIGH 7.5
CVE-2025-58446

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer introduced in 0.1.23 processes la…

Patch available
Fix from $1,950 2025-09-06
Ada Web Server HIGH 7.5
CVE-2025-52494

Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes during conne…

Fix: 26.0+
Fix from $1,950 2025-09-03
Flight HIGH 7.5
CVE-2014-125127

The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager loading of request bodies in…

Fix: 1.2+
Fix from $1,950 2025-09-03
Build Of Apache Camel For Spring Boot HIGH 7.5
CVE-2025-9784

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, ref…

Patch available
Fix from $1,950 2025-09-02
Unclassified HIGH 8.2
CVE-2024-58259

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated)…

Mitigation only
Fix from $1,950 2025-09-02
File Station MEDIUM 6.5
CVE-2025-29899

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.4907+
Fix from $1,600 2025-08-29
File Station MEDIUM 6.5
CVE-2025-29900

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.4907+
Fix from $1,600 2025-08-29
Qsync Central MEDIUM 6.5
CVE-2025-30260

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…

Fix: 4.5.0.7+
Fix from $1,600 2025-08-29