Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified MEDIUM 6.5
CVE-2026-67199

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.9
CVE-2026-18401

The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default…

No fix yet
Fix from $1,600 2026-08-04
Brace Expansion HIGH 7.5
CVE-2026-69152

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() doe…

Fix: 1.1.18 / 2.1.4+
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-69079

CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a …

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-13586

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-58063

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-20482

In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-59647

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS be…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-59648

In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java L…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-15055

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.9
CVE-2025-71401

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An …

No fix yet
Fix from $1,600 2026-08-02
Guardian HIGH 7.5
CVE-2026-55733

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-control…

Fix: 2.4.1+
Fix from $1,950 2026-08-01
Guardian HIGH 7.5
CVE-2026-55734

Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via…

Fix: 2.4.1+
Fix from $1,950 2026-08-01
Guardian HIGH 7.5
CVE-2026-54894

Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influen…

Fix: 2.4.1+
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-67353

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields w…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67317

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length ca…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67297

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body()…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-55497

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed fil…

No fix yet
Fix from $1,600 2026-07-31
Mcp Toolbox For Databases HIGH 7.5
CVE-2026-14539

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows…

Fix: 1.5.0+
Fix from $1,950 2026-07-31
Datapower Gateway HIGH 7.5
CVE-2026-12733

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

Fix: 10.5.0.22 / 10.6.0.10+
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-16308

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial…

No fix yet
Fix from $1,950 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-11897

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted requ…

Fix: 26.0.0.8+
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.9
CVE-2026-16971

The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.9
CVE-2026-18362

The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-67437

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_au…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.5
CVE-2026-67432

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-67430

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.2
CVE-2026-63119

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MC…

No fix yet
Fix from $1,600 2026-07-29
GitLab HIGH 7.5
CVE-2026-15975

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under …

Fix: 19.0.5 / 19.1.3+
Fix from $1,950 2026-07-29
Netty HIGH 7.5
CVE-2026-59899

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the sup…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-29