Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2026-50142 libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memo… Fix unknown Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-52732 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Z… Fix unknown Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-47628 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successf… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-74039 Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to … Fix unknown Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-73997 Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-47683 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(… Fix unknown Fix from $4,9002026-08-17 HIGH 7.1 CVE-2026-75050 In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters Fix unknown Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-64868 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webho… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-74878 openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on … Fix unknown Fix from $5,7502026-08-17 HIGH 8.7 CVE-2026-74784 Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respect… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.5 CVE-2026-74786 Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) ca… No fix yet Fix from $4,0002026-08-16 HIGH 7.5 CVE-2026-74788 Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_righ… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-73060 Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-73062 Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enf… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.5 CVE-2026-72888 Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require. smart_require stores… Fix unknown Fix from $4,0002026-08-16 HIGH 7.5 CVE-2026-19474 @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can… No fix yet Fix from $4,9002026-08-15 HIGH 7.5 CVE-2026-73635 Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localize… Struts Fix unknown Fix from $4,9002026-08-15 MEDIUM 5.3 CVE-2026-19830 A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.5 CVE-2026-72838 FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated use… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.5 CVE-2026-19617 A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures… No fix yet Fix from $4,0002026-08-14 HIGH 7.5 CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client pre… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-56862 Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a re… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-17076 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72684 A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72674 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72667 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A spec… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72659 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specia… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72651 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authe… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72653 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authe… No fix yet Fix from $4,0002026-08-13