Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Safari MEDIUM 6.2
CVE-2025-43211

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.…

Fix: 2.6 / 11.6+
Fix from $1,600 2025-07-30
Unclassified MEDIUM 6.5
CVE-2025-5253

Allocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS. This issue affects Kron PAM: befor…

Mitigation only
Fix from $1,600 2025-07-25
Suricata HIGH 7.5
CVE-2025-53538

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.…

Fix: 7.0.11+
Fix from $1,950 2025-07-22
Unclassified MEDIUM 5.3
CVE-2025-54121

Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In ver…

Patch available
Fix from $1,600 2025-07-21
Rax30 Firmware HIGH 7.5
CVE-2025-44652

In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when…

Mitigation only
Fix from $1,950 2025-07-21
Cpp Httplib HIGH 8.8
CVE-2025-53628

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique lin…

Fix: 0.20.1+
Fix from $1,950 2025-07-10
Cpp Httplib HIGH 7.5
CVE-2025-53629

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked…

Fix: 0.23.0+
Fix from $1,950 2025-07-10
Chall Manager HIGH 7.5
CVE-2025-53634

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout s…

Fix: 0.1.4+
Fix from $1,950 2025-07-10
Wegia HIGH 7.5
CVE-2025-53530

WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific…

Fix: 3.3.0+
Fix from $1,950 2025-07-07
Wegia HIGH 7.5
CVE-2025-53531

WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific…

Fix: 3.3.0+
Fix from $1,950 2025-07-07
Redis HIGH 7.5
CVE-2025-48367

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to cl…

Fix: 6.2.19 / 7.2.10+
Fix from $1,950 2025-07-07
Q9 Firmware HIGH 8.8
CVE-2025-7070

A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functio…

Fix: after 2025-06-24
Fix from $1,950 2025-07-04
GitLab MEDIUM 6.5
CVE-2025-3279

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could h…

Fix: 17.11.5 / 18.0.3+
Fix from $1,600 2025-06-26
Unclassified HIGH 7.5
CVE-2025-2403

A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO …

Mitigation only
Fix from $1,950 2025-06-24
Unclassified HIGH 8.8
CVE-2025-52568

NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory cor…

Patch available
Fix from $1,950 2025-06-24
Wise 4010lan Firmware MEDIUM 6.5
CVE-2025-48467

Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to remote denial-of-service and s…

No fix yet
Fix from $1,600 2025-06-24
Infosphere Information Server HIGH 7.5
CVE-2025-3221

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation…

Fix: after 11.7.1.6
Fix from $1,950 2025-06-21
Quiche MEDIUM 5.3
CVE-2025-4820

Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t…

Fix: 0.24.4+
Fix from $1,600 2025-06-18
Quiche HIGH 7.5
CVE-2025-4821

Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t…

Fix: 0.24.4+
Fix from $1,950 2025-06-18
Commons Fileupload HIGH 7.5
CVE-2025-48976EPSS 68%

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects …

Fix: 1.6+
Fix from $1,950 2025-06-16
Tomcat HIGH 7.5
CVE-2025-48988EPSS 57%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7…

Fix: 9.0.106 / 10.1.42+
Fix from $1,950 2025-06-16
GitLab MEDIUM 6.5
CVE-2025-5996

An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack o…

Fix: 17.10.8 / 17.11.4+
Fix from $1,600 2025-06-12
GitLab HIGH 7.5
CVE-2025-1516

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper i…

Fix: 17.10.8 / 17.11.4+
Fix from $1,950 2025-06-12
GitLab HIGH 7.5
CVE-2025-1478

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of…

Fix: 17.10.7 / 17.11.3+
Fix from $1,950 2025-06-12
Cognos Analytics HIGH 7.5
CVE-2025-25032

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a …

Fix: after 12.0.4
Fix from $1,950 2025-06-11
Admin Audit Trail MEDIUM 6.5
CVE-2025-48448

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin A…

Fix: 1.0.5+
Fix from $1,600 2025-06-11
Maya MEDIUM 6.6
CVE-2025-4605

A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may…

Fix: 2025.3.1+
Fix from $1,600 2025-06-11
Unclassified HIGH 7.5
CVE-2025-49140

Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a bug in a RTP packet factory …

Patch available
Fix from $1,950 2025-06-09
Discourse HIGH 7.5
CVE-2025-48053

Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version…

Fix: 3.4.4 / 3.5.0+
Fix from $1,950 2025-06-09
Unclassified MEDIUM 5.7
CVE-2025-25207

The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with deve…

Mitigation only
Fix from $1,600 2025-06-09