Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified HIGH 7.5
CVE-2025-31496

apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Compiler allowed queries with de…

Patch available
Fix from $1,950 2025-04-07
Unclassified MEDIUM 5.3
CVE-2025-24317

Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthe…

Mitigation only
Fix from $1,600 2025-04-04
Unclassified HIGH 7.5
CVE-2025-32049

A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to…

Mitigation only
Fix from $1,950 2025-04-03
Django HIGH 7.5
CVE-2025-27556

An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib…

Fix: 5.0.14 / 5.1.8+
Fix from $1,950 2025-04-02
Zabbix MEDIUM 6.5
CVE-2024-45700

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the se…

Fix: 6.0.39 / 7.0.10+
Fix from $1,600 2025-04-02
GitLab MEDIUM 5.5
CVE-2024-10307

An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. A malicio…

Fix: 17.8.6 / 17.9.3+
Fix from $1,600 2025-03-28
Directus MEDIUM 5.3
CVE-2025-30350

Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0…

Fix: 11.5.0+
Fix from $1,600 2025-03-26
Directus MEDIUM 5.3
CVE-2025-30225

Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0…

Fix: 11.5.0+
Fix from $1,600 2025-03-26
Unclassified HIGH 7.2
CVE-2024-45484

An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used in B&R APROL <4.4-00P5 may a…

Mitigation only
Fix from $1,950 2025-03-25
Lollms Web Ui HIGH 7.5
CVE-2025-1451

A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or …

No fix yet
Fix from $1,950 2025-03-20
Ollama HIGH 7.5
CVE-2025-0315

A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create …

Fix: after 0.3.14
Fix from $1,950 2025-03-20
Aim HIGH 7.5
CVE-2025-0189

In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websock…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2025-0182

A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulner…

Mitigation only
Fix from $1,950 2025-03-20
Superagi HIGH 7.5
CVE-2024-9437

SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in the resource upload request,…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2024-9229

A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated attackers to cause excessive r…

Mitigation only
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2024-9056

BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as da…

Mitigation only
Fix from $1,950 2025-03-20
Video HIGH 7.5
CVE-2024-8966

A vulnerability in the file upload process of gradio-app/gradio version @gradio/[email protected] allows for a Denial of Service (DoS) attack. An attacker…

Patch available
Fix from $1,950 2025-03-20
Litellm HIGH 7.5
CVE-2024-8984

A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such …

Fix: 1.65.4+
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2024-8028

A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart bo…

Mitigation only
Fix from $1,950 2025-03-20
Open Webui HIGH 7.5
CVE-2024-7983

In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload…

No fix yet
Fix from $1,950 2025-03-20
Privategpt HIGH 7.5
CVE-2024-8018

A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a la…

No fix yet
Fix from $1,950 2025-03-20
H2o HIGH 7.5
CVE-2024-7768

A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a …

No fix yet
Fix from $1,950 2025-03-20
Aim HIGH 7.5
CVE-2024-12778

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics a…

No fix yet
Fix from $1,950 2025-03-20
Open Webui HIGH 7.5
CVE-2024-12537

In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/…

No fix yet
Fix from $1,950 2025-03-20
Librechat HIGH 7.5
CVE-2024-11171

In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses multer middleware for handlin…

Fix: 0.7.6+
Fix from $1,950 2025-03-20
Stable Diffusion Webui HIGH 7.5
CVE-2024-10935

automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the en…

No fix yet
Fix from $1,950 2025-03-20
Chuanhuchatgpt HIGH 7.5
CVE-2024-10650

An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could be exploited by sending large…

No fix yet
Fix from $1,950 2025-03-20
Unclassified HIGH 7.5
CVE-2024-10713

A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle excessive characters appended to …

Mitigation only
Fix from $1,950 2025-03-20
Gpt Academic HIGH 7.5
CVE-2024-10714

A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the…

No fix yet
Fix from $1,950 2025-03-20
Llava HIGH 7.5
CVE-2024-10225

A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the en…

No fix yet
Fix from $1,950 2025-03-20