Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Coredns HIGH 7.5
CVE-2025-47950

CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC…

Fix: 1.12.2+
Fix from $1,950 2025-06-06
Unclassified HIGH 7.1
CVE-2025-22484

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user …

Mitigation only
Fix from $1,950 2025-06-06
File Station HIGH 7.5
CVE-2025-29872

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user …

Fix: 5.5.6.4847+
Fix from $1,950 2025-06-06
Qt MEDIUM 5.5
CVE-2025-5683

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 throug…

Fix: 6.5.10 / 6.8.5+
Fix from $1,600 2025-06-05
Rack MEDIUM 5.3
CVE-2025-49007

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the…

Fix: 3.1.16+
Fix from $1,600 2025-06-04
Unclassified HIGH 7.5
CVE-2018-25112

An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected products by creating large a…

Mitigation only
Fix from $1,950 2025-06-04
Inventree MEDIUM 5.7
CVE-2025-49000

InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper…

Fix: 0.17.13+
Fix from $1,600 2025-06-03
Unclassified HIGH 8.7
CVE-2025-46807

A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny…

Mitigation only
Fix from $1,950 2025-06-02
Db2 MEDIUM 6.5
CVE-2025-3050

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user t…

Fix: after 12.1.1
Fix from $1,600 2025-05-29
Unclassified MEDIUM 6.9
CVE-2025-48738

An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows u…

Mitigation only
Fix from $1,600 2025-05-23
Schule School Management System MEDIUM 5.3
CVE-2025-48375

Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for…

No fix yet
Fix from $1,600 2025-05-23
GitLab HIGH 7.5
CVE-2024-7803

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord…

Fix: 17.10.7 / 17.11.3+
Fix from $1,950 2025-05-23
GitLab MEDIUM 6.5
CVE-2025-0993

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an…

Fix: 17.10.7 / 17.11.3+
Fix from $1,600 2025-05-22
GitLab MEDIUM 6.5
CVE-2025-2853

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper va…

Fix: 17.10.7 / 17.11.3+
Fix from $1,600 2025-05-22
GitLab MEDIUM 6.5
CVE-2025-3111

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of…

Fix: 17.10.7 / 17.11.3+
Fix from $1,600 2025-05-22
Events Log Track HIGH 7.5
CVE-2025-4416

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events L…

Fix: 3.1.11 / 4.0.2+
Fix from $1,950 2025-05-21
Group Folders MEDIUM 6.5
CVE-2025-47793

Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a…

Fix: 16.0.11 / 17.0.5+
Fix from $1,600 2025-05-16
Debian Linux HIGH 7.5
CVE-2025-47287

Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo…

Fix: 6.5.0+
Fix from $1,950 2025-05-15
Windows 10 1507 MEDIUM 5.9
CVE-2025-29954

Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw…

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows 10 1507 MEDIUM 6.2
CVE-2025-29957

Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,600 2025-05-13
Windows Server 2016 HIGH 7.5
CVE-2025-26677

Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.8066 / 10.0.17763.7314+
Fix from $1,950 2025-05-13
4769 Developers Toolkit HIGH 7.5
CVE-2025-3632

IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due…

Fix: 7.5.62+
Fix from $1,950 2025-05-12
GitLab HIGH 7.5
CVE-2024-8973

An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 p…

Fix: 17.9.8 / 17.10.6+
Fix from $1,950 2025-05-09
Unclassified MEDIUM 5.3
CVE-2025-4432

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attack…

Patch available
Fix from $1,600 2025-05-09
Linux Kernel MEDIUM 5.5
CVE-2025-37805

In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitialized work_structs Betty repo…

Fix: 5.15.181 / 6.1.136+
Fix from $1,600 2025-05-08
Django MEDIUM 5.3
CVE-2025-32873EPSS 14%

An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerabl…

Fix: 4.2.21 / 5.1.9+
Fix from $1,600 2025-05-08
Rack HIGH 7.5
CVE-2025-46727

Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/…

Fix: 2.2.14 / 3.0.16+
Fix from $1,950 2025-05-07
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-36504

When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization…

Fix: 16.1.6 / 17.1.2+
Fix from $1,950 2025-05-07
Db2 MEDIUM 6.5
CVE-2025-1000

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user…

Fix: after 12.1.1
Fix from $1,600 2025-05-05
Db2 MEDIUM 6.5
CVE-2025-0915

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations c…

Fix: after 12.1.1
Fix from $1,600 2025-05-05