Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Fastify\/rate Limit MEDIUM 5.3
CVE-2026-15144

@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can…

Fix: 11.2.0+
Fix from $1,600 2026-07-29
Unclassified HIGH 7.5
CVE-2026-54638

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker con…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.6
CVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards REC…

No fix yet
Fix from $1,950 2026-07-28
Gopacket HIGH 7.5
CVE-2026-54332

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads…

Fix: 1.6.1+
Fix from $1,950 2026-07-28
Gopacket HIGH 7.5
CVE-2026-54345

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtra…

Fix: 1.6.1+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-61609

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProv…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.2
CVE-2026-47483

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource co…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.7
CVE-2026-59248

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on …

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-65624

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connectio…

No fix yet
Fix from $1,600 2026-07-28
Next.js MEDIUM 5.3
CVE-2026-64646

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests target…

Fix: 15.5.21 / 16.2.11+
Fix from $1,600 2026-07-27
Erlang\/otp HIGH 7.5
CVE-2026-59251

Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial …

Fix: 1.17.1.5 / 1.20.3.4+
Fix from $1,950 2026-07-27
Erlang\/otp HIGH 7.5
CVE-2026-42792

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminat…

Fix: 15.2.7.11 / 16.4.0.4+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-58389

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. …

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-55968

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Thrift HIGH 7.5
CVE-2026-45112

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 bef…

Fix: 0.24.0+
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.3
CVE-2026-17501

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp …

No fix yet
Fix from $1,600 2026-07-27
Ffmpeg MEDIUM 5.5
CVE-2026-66037

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthe…

Fix: after 8.1.2
Fix from $1,600 2026-07-24
Unclassified HIGH 7.5
CVE-2026-25800

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, th…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.5
CVE-2026-16756

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-serv…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.5
CVE-2026-14257

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max…

No fix yet
Fix from $1,950 2026-07-23
MongoDB MEDIUM 5.3
CVE-2026-13074

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the await…

No fix yet
Fix from $1,600 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13075

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusio…

No fix yet
Fix from $1,600 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13076

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data typ…

No fix yet
Fix from $1,600 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13069

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption f…

Fix: 7.0.39 / 8.0.28+
Fix from $1,600 2026-07-22
Unclassified HIGH 7.5
CVE-2026-11622

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker …

No fix yet
Fix from $1,950 2026-07-22
Jdk MEDIUM 5.3
CVE-2026-47013

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerabil…

No fix yet
Fix from $1,600 2026-07-21
Kibana MEDIUM 6.5
CVE-2026-42397

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An aut…

Fix: 9.3.7 / 9.4.4+
Fix from $1,600 2026-07-21
Unclassified HIGH 7.5
CVE-2026-15957

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS…

No fix yet
Fix from $1,950 2026-07-21
Hardened Images MEDIUM 5.3
CVE-2026-59848

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing …

No fix yet
Fix from $1,600 2026-07-21
Netty HIGH 7.5
CVE-2026-55831

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTI…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-21