Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Rabbitmq Server HIGH 7.7
CVE-2026-57212

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid J…

Fix: 4.2.5+
Fix from $1,950 2026-07-10
Excelize HIGH 7.5
CVE-2026-59161

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows …

Fix: 2.11.0+
Fix from $1,950 2026-07-10
Excelize HIGH 7.5
CVE-2026-54063

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/xuri…

Fix: 2.11.0+
Fix from $1,950 2026-07-10
Unclassified HIGH 8.7
CVE-2026-53653

Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by request…

Patch available
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-58661

n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-56309

Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create public…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.9
CVE-2026-56814

Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget agains…

Patch available
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40006

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulne…

Mitigation only
Fix from $1,950 2026-07-10
Zeek HIGH 7.5
CVE-2026-60108

Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause…

Fix: 8.0.9+
Fix from $1,950 2026-07-09
Body Parser MEDIUM 5.9
CVE-2026-12590

Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value suc…

Fix: 1.20.6 / 2.3.0+
Fix from $1,600 2026-07-09
Cmc HIGH 7.5
CVE-2026-31984

A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size li…

Fix: 26.2.0+
Fix from $1,950 2026-07-09
Unclassified HIGH 7.5
CVE-2026-49866

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs an…

Patch available
Fix from $1,950 2026-07-08
Unclassified HIGH 8.2
CVE-2026-55575

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filter at src/filters/array.ts al…

Patch available
Fix from $1,950 2026-07-08
Js Yaml HIGH 7.5
CVE-2026-59868

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a …

Fix: 5.2.0+
Fix from $1,950 2026-07-08
Js Yaml HIGH 7.5
CVE-2026-59870

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src/tag/sequence/omap.ts uses om…

Fix: 5.2.1+
Fix from $1,950 2026-07-08
Tar HIGH 7.5
CVE-2026-59873

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, …

Fix: 7.5.19+
Fix from $1,950 2026-07-08
Unclassified HIGH 7.5
CVE-2026-49146

App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ack searches up the directory h…

Patch available
Fix from $1,950 2026-07-08
Openssh HIGH 7.5
CVE-2026-60000

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) becaus…

Fix: 10.4+
Fix from $1,950 2026-07-08
Openssh MEDIUM 6.5
CVE-2026-60001

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

Fix: 10.4+
Fix from $1,600 2026-07-08
Coder MEDIUM 6.5
CVE-2026-55078

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.…

Fix: 2.29.17 / 2.32.7+
Fix from $1,600 2026-07-07
Coder MEDIUM 6.5
CVE-2026-55434

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.…

Fix: 2.33.8 / 2.34.2+
Fix from $1,600 2026-07-07
Phoenix HIGH 7.5
CVE-2026-56811

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated atta…

Fix: 1.5.15 / 1.6.17+
Fix from $1,950 2026-07-07
Unclassified MEDIUM 6.5
CVE-2026-41899

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has n…

Patch available
Fix from $1,600 2026-07-06
Vllm MEDIUM 6.5
CVE-2026-55646

vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations rou…

Fix: 0.24.0+
Fix from $1,600 2026-07-06
Openvpn HIGH 7.5
CVE-2026-13698

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-cry…

Fix: 2.6.21 / 2.7.5+
Fix from $1,950 2026-07-06
Unclassified HIGH 8.7
CVE-2026-56810

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a denial of service via an oversize…

Patch available
Fix from $1,950 2026-07-06
Curl HIGH 7.5
CVE-2026-11586

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a…

Fix: 8.21.0+
Fix from $1,950 2026-07-03
Unclassified HIGH 7.5
CVE-2026-58465

Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that …

Patch available
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-11946

An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpoin…

Patch available
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-9563

In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of charact…

Patch available
Fix from $1,950 2026-07-02