Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Qsync Central MEDIUM 6.5
CVE-2025-30261

An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…

Mitigation only
Fix from $1,600 2025-08-29
File Station MEDIUM 6.5
CVE-2025-29890

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a…

Fix: 5.5.6.4907+
Fix from $1,600 2025-08-29
Qsync Central MEDIUM 6.5
CVE-2025-29898

An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can the…

Fix: 4.5.0.7+
Fix from $1,600 2025-08-29
Unclassified MEDIUM 5.3
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-enco…

Patch available
Fix from $1,600 2025-08-28
Vault HIGH 7.5
CVE-2025-6203

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory…

Fix: 1.16.27 / 1.18.15+
Fix from $1,950 2025-08-28
GitLab MEDIUM 6.5
CVE-2025-3601

An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could ha…

Fix: 18.1.5 / 18.2.5+
Fix from $1,600 2025-08-27
GitLab HIGH 7.5
CVE-2025-4225

An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that und…

Fix: 18.1.5 / 18.2.5+
Fix from $1,950 2025-08-27
Jspdf HIGH 7.5
CVE-2025-57810

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilizati…

Fix: 3.0.2+
Fix from $1,950 2025-08-26
Digital Experience Platform MEDIUM 6.5
CVE-2025-43762

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.…

Fix: 2024.Q1.15 / 2025.Q1.2+
Fix from $1,600 2025-08-22
Digital Experience Platform MEDIUM 6.5
CVE-2025-43752

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.…

Fix: 2024.Q1.16 / 2025.Q1.5+
Fix from $1,600 2025-08-22
Unclassified MEDIUM 5.7
CVE-2025-4437

There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-…

Mitigation only
Fix from $1,600 2025-08-20
Websphere Application Server HIGH 7.5
CVE-2025-36047

IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted reques…

Fix: 25.0.0.9+
Fix from $1,950 2025-08-14
Helm MEDIUM 6.5
CVE-2025-55199

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could caus…

Fix: 3.18.5+
Fix from $1,600 2025-08-14
Pypdf HIGH 7.5
CVE-2025-55197

pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. …

Fix: 6.0.0+
Fix from $1,950 2025-08-13
GitLab MEDIUM 6.5
CVE-2025-2614

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could ha…

Fix: 18.0.6 / 18.1.4+
Fix from $1,600 2025-08-13
GitLab HIGH 7.5
CVE-2025-1477

An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could ha…

Fix: 18.0.6 / 18.1.4+
Fix from $1,950 2025-08-13
Netty HIGH 7.5
CVE-2025-55163

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYou…

Fix: 4.1.124 / 4.2.4+
Fix from $1,950 2025-08-13
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2025-54500

An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams…

Fix: 15.1.10.8 / 16.1.6.1+
Fix from $1,600 2025-08-13
Unclassified MEDIUM 6.3
CVE-2025-8916

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of…

Mitigation only
Fix from $1,600 2025-08-13
Windows 10 1809 MEDIUM 6.5
CVE-2025-50172

Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network.

Fix: 10.0.17763.7678 / 10.0.19044.6216+
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.3
CVE-2025-8885

Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified HIGH 8.7
CVE-2025-54884

Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and…

Patch available
Fix from $1,950 2025-08-06
Unclassified MEDIUM 6.0
CVE-2025-54869

FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. In versions 2.6.2 …

Patch available
Fix from $1,600 2025-08-06
Mastodon HIGH 7.5
CVE-2025-54879

Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versi…

Fix: 4.2.24 / 4.3.11+
Fix from $1,950 2025-08-06
Bento4 MEDIUM 5.9
CVE-2025-8537

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetData…

Fix: after 1.6.0-641
Fix from $1,600 2025-08-05
Openexr MEDIUM 5.5
CVE-2025-48074

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In v…

No fix yet
Fix from $1,600 2025-08-01
Litespeed Web Adc HIGH 7.5
CVE-2025-54939

LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.

Fix: 1.8.4 / 3.3.1+
Fix from $1,950 2025-08-01
Unclassified HIGH 7.5
CVE-2025-2813

An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80.

Mitigation only
Fix from $1,950 2025-07-31
Unclassified MEDIUM 5.3
CVE-2025-54575

ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment e…

Patch available
Fix from $1,600 2025-07-30
Unclassified MEDIUM 6.9
CVE-2025-54572

The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability ex…

Patch available
Fix from $1,600 2025-07-30