Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified HIGH 7.5
CVE-2026-33592

An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersR…

Patch available
Fix from $1,950 2026-07-02
Httpcomponents Core HIGH 7.5
CVE-2026-54428

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl…

Fix: after 5.4.2
Fix from $1,950 2026-07-01
Fleet Server HIGH 7.5
CVE-2026-56150

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). …

Fix: 8.19.11 / 9.2.5+
Fix from $1,950 2026-07-01
Kibana MEDIUM 6.5
CVE-2026-49087

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An aut…

Fix: 8.19.15 / 9.3.4+
Fix from $1,600 2026-07-01
Secure Endpoint HIGH 7.5
CVE-2026-20216

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affe…

Fix: 1.4.5 / 1.5.3+
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.5
CVE-2026-14330

Multiple unbounded alloca() calls in the PulseAudio protocol server.

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-57080

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framin…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-12818

Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP …

Mitigation only
Fix from $2,300 2026-06-30
Unclassified HIGH 8.2
CVE-2026-53426

Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a {:…

Patch available
Fix from $1,950 2026-06-29
Unclassified MEDIUM 5.3
CVE-2025-32394

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is …

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.3
CVE-2025-32423

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is …

Mitigation only
Fix from $1,600 2026-06-26
Node.js HIGH 7.5
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affe…

Patch available
Fix from $1,950 2026-06-26
Librechat MEDIUM 6.5
CVE-2026-54037

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-7105 added forkIpLimiter and for…

Fix: after 0.8.3
Fix from $1,600 2026-06-25
Trivy MEDIUM 6.5
CVE-2026-54448

Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(…

Fix: 0.71.0+
Fix from $1,600 2026-06-25
Librechat MEDIUM 6.5
CVE-2026-54024

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-11171 (commit bb58a2d0) added li…

Fix: after 0.8.3
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.3
CVE-2026-40211

An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will …

Mitigation only
Fix from $1,600 2026-06-25
Tapo C200 Firmware MEDIUM 6.5
CVE-2026-12760

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fra…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.5
CVE-2026-49851

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (app…

Mitigation only
Fix from $1,950 2026-06-24
Faraday HIGH 7.5
CVE-2026-54297

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday:…

Fix: 1.10.6 / 2.14.3+
Fix from $1,950 2026-06-24
Unclassified HIGH 8.2
CVE-2026-11972

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive par…

Patch available
Fix from $1,950 2026-06-23
Unclassified MEDIUM 6.5
CVE-2026-46551

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, the uploadViaURL path in the v1/v2 attachment API did not enforce NC_A…

Mitigation only
Fix from $1,600 2026-06-23
Unclassified HIGH 7.5
CVE-2025-61028

An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st…

Mitigation only
Fix from $1,950 2026-06-23
Go HIGH 7.5
CVE-2023-54365

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard libr…

Fix: 1.20.10 / 1.21.3+
Fix from $1,950 2026-06-23
Unclassified HIGH 8.2
CVE-2026-56324

Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by ro…

Mitigation only
Fix from $1,950 2026-06-22
Messagepack HIGH 7.5
CVE-2026-48514

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserialize reads an attacker-controlle…

Fix: 2.5.301 / 3.1.7+
Fix from $1,950 2026-06-22
Messagepack HIGH 7.5
CVE-2026-48515

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimen…

Fix: 2.5.301 / 3.1.7+
Fix from $1,950 2026-06-22
Messagepack HIGH 7.5
CVE-2026-48510

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray pay…

Fix: 2.5.301 / 3.1.7+
Fix from $1,950 2026-06-22
Unclassified MEDIUM 6.5
CVE-2026-39904

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uplo…

Mitigation only
Fix from $1,600 2026-06-22
Unclassified MEDIUM 5.3
CVE-2026-54285

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size …

Mitigation only
Fix from $1,600 2026-06-22
Aiohttp HIGH 7.5
CVE-2026-54277

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in …

Fix: 3.14.1+
Fix from $1,950 2026-06-22