Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Realchar HIGH 7.5
CVE-2024-10051

Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in the file upload request handl…

No fix yet
Fix from $1,950 2025-03-20
Vllm MEDIUM 6.5
CVE-2025-29770

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. The outlines library is one of the backends used by vLLM to sup…

Fix: 0.8.0+
Fix from $1,600 2025-03-19
Jspdf HIGH 7.5
CVE-2025-29907

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.1, user control of the first argument of the addImage method results in CPU utilizati…

Fix: 3.0.1+
Fix from $1,950 2025-03-18
Unclassified HIGH 7.5
CVE-2025-29786

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input s…

Patch available
Fix from $1,950 2025-03-17
GitLab HIGH 7.5
CVE-2025-1257

An issue was discovered in GitLab EE affecting all versions starting with 12.3 before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. A vulne…

Fix: 17.7.7 / 17.8.5+
Fix from $1,950 2025-03-13
GitLab MEDIUM 6.5
CVE-2024-13054

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of servi…

Fix: 17.7.7 / 17.8.5+
Fix from $1,600 2025-03-13
Ios Xr HIGH 7.5
CVE-2025-20209

A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to p…

Mitigation only
Fix from $1,950 2025-03-12
Ios Xr HIGH 7.4
CVE-2025-20141

A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 coul…

Mitigation only
Fix from $1,950 2025-03-12
Linux Kernel MEDIUM 5.5
CVE-2025-21866

In the Linux kernel, the following vulnerability has been resolved: powerpc/code-patching: Fix KASAN hit by not flagging text patching area as VM_AL…

Fix: 6.1.130 / 6.6.80+
Fix from $1,600 2025-03-12
Linux Kernel MEDIUM 5.5
CVE-2024-58089

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_delalloc_range() failed [BUG] …

Fix: 6.12.17 / 6.13.5+
Fix from $1,600 2025-03-12
Seq MEDIUM 6.5
CVE-2025-27911

An issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system "Event bo…

Fix: 2024.3.13545+
Fix from $1,600 2025-03-11
Graphicsmagick HIGH 7.5
CVE-2025-27795

ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.

Fix: 1.3.46+
Fix from $1,950 2025-03-07
Unclassified MEDIUM 6.5
CVE-2024-57972

The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10…

Mitigation only
Fix from $1,600 2025-03-06
Django HIGH 7.5
CVE-2025-26699

An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap templa…

Fix: 4.2.20 / 5.0.13+
Fix from $1,950 2025-03-06
Unclassified HIGH 7.5
CVE-2025-27513

OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (…

Patch available
Fix from $1,950 2025-03-05
Cgi HIGH 7.5
CVE-2025-27219

In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The…

Fix: 0.3.5.1 / 0.4.2+
Fix from $1,950 2025-03-04
Wegia HIGH 7.5
CVE-2025-27419

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Denial of Service (DoS) vulnerability exists in WeG…

Fix: 3.2.16+
Fix from $1,950 2025-03-03
Ubuntu Linux MEDIUM 5.9
CVE-2025-26466EPSS 40%

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a …

Mitigation only
Fix from $1,600 2025-02-28
Unclassified CRITICAL 9.3
CVE-2025-22273

Application does not limit the number or frequency of user interactions, such as the number of incoming requests. At the "/EPMUI/VfManager.asmx/Chang…

Mitigation only
Fix from $2,300 2025-02-28
Mastodon MEDIUM 5.3
CVE-2025-27157

Mastodon is a self-hosted, federated microblogging platform. Starting in version 4.2.0 and prior to versions 4.2.16 and 4.3.4, the rate limits are mi…

Fix: 4.2.16 / 4.3.4+
Fix from $1,600 2025-02-27
Ssh HIGH 7.5
CVE-2025-22869

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly,…

Fix: 0.35.0+
Fix from $1,950 2025-02-26
Unclassified MEDIUM 6.6
CVE-2025-27144

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption …

Patch available
Fix from $1,600 2025-02-24
Event Ticketing System MEDIUM 6.5
CVE-2023-51339

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of em…

No fix yet
Fix from $1,600 2025-02-20
Unclassified HIGH 7.7
CVE-2024-46933

An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without…

Mitigation only
Fix from $1,950 2025-02-20
Cinema Booking System MEDIUM 5.3
CVE-2023-51334

A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of ema…

No fix yet
Fix from $1,600 2025-02-20
Hotel Booking System MEDIUM 6.5
CVE-2023-51297

A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email…

No fix yet
Fix from $1,600 2025-02-19
Unclassified MEDIUM 6.5
CVE-2024-49589

Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied argument…

Mitigation only
Fix from $1,600 2025-02-18
Monero HIGH 7.5
CVE-2025-26819

Monero through 0.18.3.4 before ec74ff4 does not have response limits on HTTP server connections.

Fix: after 0.18.3.4
Fix from $1,950 2025-02-15
Unclassified HIGH 7.5
CVE-2025-1059

CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause communications to stop when malicious packets are…

Mitigation only
Fix from $1,950 2025-02-13
GitLab MEDIUM 6.5
CVE-2024-12379

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 al…

Fix: 17.6.5 / 17.7.4+
Fix from $1,600 2025-02-12