Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified HIGH 8.2
CVE-2025-32777

Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.…

Mitigation only
Fix from $1,950 2025-04-30
Unclassified MEDIUM 6.5
CVE-2025-24341

A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to induce a Denial-of-Service (DoS) condit…

Mitigation only
Fix from $1,600 2025-04-30
Vllm HIGH 7.5
CVE-2025-30202

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and prior to 0.8.5 are vulnerable …

Fix: 0.8.5+
Fix from $1,950 2025-04-30
Net\ MEDIUM 6.5
CVE-2025-43857

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4.20, 0.3.9, and 0.2.5, there i…

Fix: 0.2.5 / 0.3.9+
Fix from $1,600 2025-04-28
Quickjs HIGH 7.8
CVE-2025-46687

quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26…

Fix: 2025-04-26+
Fix from $1,950 2025-04-27
Unclassified MEDIUM 5.5
CVE-2025-30409

Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) bef…

Mitigation only
Fix from $1,600 2025-04-24
GitLab HIGH 7.5
CVE-2025-0639

An issue has been discovered affecting service availability via issue preview in GitLab CE/EE affecting all versions from 16.7 before 17.9.7, 17.10 b…

Fix: 17.9.7 / 17.10.5+
Fix from $1,950 2025-04-24
Mattermost Server HIGH 7.5
CVE-2025-35965

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the Upd…

Fix: 9.11.11 / 10.4.3+
Fix from $1,950 2025-04-24
Redis HIGH 7.5
CVE-2025-21605

Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can caus…

Fix: 6.2.18 / 7.2.8+
Fix from $1,950 2025-04-23
Cuba Platform MEDIUM 6.5
CVE-2025-32952

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the…

Fix: 1.1.1 / 1.6.2+
Fix from $1,600 2025-04-22
Unclassified MEDIUM 6.5
CVE-2025-32959

CUBA Platform is a high level framework for enterprise applications development. Prior to version 7.2.23, the local file storage implementation does …

Patch available
Fix from $1,600 2025-04-22
Stage File Proxy MEDIUM 5.9
CVE-2025-3734

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Stage File Proxy allows Flooding.This issue affects Stage File Proxy: fr…

Fix: 3.1.5+
Fix from $1,600 2025-04-16
Unclassified MEDIUM 5.1
CVE-2025-0122

A denial-of-service (DoS) vulnerability in Palo Alto Networks Prisma® SD-WAN ION devices enables an unauthenticated attacker in a network adjacent to…

Mitigation only
Fix from $1,600 2025-04-11
Qradar Wincollect MEDIUM 6.5
CVE-2024-51461

IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupting an HTTP request that coul…

Fix: 10.1.14+
Fix from $1,600 2025-04-11
Suricata MEDIUM 5.5
CVE-2025-29917

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. The bytes setting in the decode…

Fix: 7.0.9+
Fix from $1,600 2025-04-10
Suricata MEDIUM 5.5
CVE-2025-29916

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Datasets declared in rules have…

Fix: 7.0.9+
Fix from $1,600 2025-04-10
GitLab HIGH 7.5
CVE-2025-1677

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A den…

Fix: 17.9.6 / 17.10.4+
Fix from $1,950 2025-04-10
Powerscale Onefs HIGH 7.5
CVE-2025-26480

Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker wi…

Fix: after 9.10.0.0
Fix from $1,950 2025-04-10
Helm MEDIUM 6.5
CVE-2025-32386

Helm is a tool for managing Charts. A chart archive file can be crafted in a manner where it expands to be significantly larger uncompressed than com…

Fix: 3.17.3+
Fix from $1,600 2025-04-09
Web T MEDIUM 6.5
CVE-2025-3475

Allocation of Resources Without Limits or Throttling, Incorrect Authorization vulnerability in Drupal WEB-T allows Excessive Allocation, Content Spoo…

Fix: 1.1.0+
Fix from $1,600 2025-04-09
Unclassified HIGH 7.5
CVE-2025-32380

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. …

Patch available
Fix from $1,950 2025-04-09
Xgrammar MEDIUM 6.5
CVE-2025-32381

XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to 0.1.18, Xgrammar includes a cache for compil…

Fix: 0.1.18+
Fix from $1,600 2025-04-09
Dotnetnuke HIGH 7.5
CVE-2025-32374

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with special…

Fix: 9.13.8+
Fix from $1,950 2025-04-09
Asp.net Core HIGH 7.5
CVE-2025-26682

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Fix: 8.0.15 / 9.0.4+
Fix from $1,950 2025-04-08
Unclassified MEDIUM 6.9
CVE-2025-32024

bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The EXIF data format allows for de…

Patch available
Fix from $1,600 2025-04-08
Unclassified MEDIUM 6.9
CVE-2025-32025

bep/imagemeta is a Go library for reading EXIF, IPTC and XMP image meta data from JPEG, TIFF, PNG, and WebP files. The buffer created for parsing met…

Patch available
Fix from $1,600 2025-04-08
Apollo Gateway HIGH 7.5
CVE-2025-32030

Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Ap…

Fix: 2.10.1+
Fix from $1,950 2025-04-07
Apollo Gateway HIGH 7.5
CVE-2025-32031

Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Ap…

Fix: 2.10.1+
Fix from $1,950 2025-04-07
Unclassified HIGH 7.5
CVE-2025-32032

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. …

Patch available
Fix from $1,950 2025-04-07
Unclassified HIGH 7.5
CVE-2025-32034

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. …

Patch available
Fix from $1,950 2025-04-07