Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified MEDIUM 5.5
CVE-2026-12570

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the …

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.5
CVE-2026-52879

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-52880

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable de…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-46405

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, o…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.5
CVE-2026-15972

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connecti…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-19015

Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roo…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2025-71411

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2025-71410

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC func…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.7
CVE-2026-67585

Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abo…

No fix yet
Fix from $1,950 2026-08-07
Cxf HIGH 7.5
CVE-2026-54225

Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no …

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-18649

A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size …

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-71321

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_islan…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71314

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island …

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.9
CVE-2026-71310

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNEC…

No fix yet
Fix from $1,600 2026-08-05
Build Of Keycloak MEDIUM 6.5
CVE-2026-16100

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account…

Fix: 26.6.5+
Fix from $1,600 2026-08-05
Unclassified HIGH 7.5
CVE-2026-59675

When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. B…

No fix yet
Fix from $1,950 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68075

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68078

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Proton Dotnet MEDIUM 6.5
CVE-2026-67553

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 1.1.0+
Fix from $1,600 2026-08-05
Qpid Proton Dotnet MEDIUM 6.5
CVE-2026-67555

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 1.1.0+
Fix from $1,600 2026-08-05
Qpid Protonj2 MEDIUM 6.5
CVE-2026-67591

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 1.2.0+
Fix from $1,600 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67592

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Proton J MEDIUM 6.5
CVE-2026-66275

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 0.35.0+
Fix from $1,600 2026-08-05
Qpid Proton J MEDIUM 6.5
CVE-2026-66277

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…

Fix: 0.35.0+
Fix from $1,600 2026-08-05
Qpid Proton Dotnet HIGH 7.5
CVE-2026-67465

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 1.1.0+
Fix from $1,950 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67588

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68060

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68074

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Proton J HIGH 7.5
CVE-2026-66257

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 0.35.0+
Fix from $1,950 2026-08-05
Unclassified HIGH 8.7
CVE-2026-68494

The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parse…

No fix yet
Fix from $1,950 2026-08-04