Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2026-54283 Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource cons… Starlette 1.3.1+ Fix from $1,9502026-06-22 MEDIUM 5.3 CVE-2026-54270 protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message.$… Protobufjs 8.5.0+ Fix from $1,6002026-06-22 HIGH 7.5 CVE-2026-54273 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requ… Aiohttp 3.14.1+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-54274 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket fram… Aiohttp 3.14.1+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-42127 The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memor… Grafana after 13.0.1 Fix from $1,9502026-06-22 MEDIUM 6.5 CVE-2024-54178 IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denia… Db2 5.4+ Fix from $1,6002026-06-22 HIGH 8.6 CVE-2025-7737 DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E10… Mitigation only Fix from $1,9502026-06-19 MEDIUM 5.3 CVE-2026-55205 Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allow… Patch available Fix from $1,6002026-06-18 MEDIUM 5.3 CVE-2026-48990 joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through… No fix yet Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-47774 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulne… Openshift Service Mesh 1.35.11 / 1.36.7+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-9675 Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A… Undici 8.5.0+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-12151 Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on th… Undici 6.27.0 / 7.28.0+ Fix from $1,9502026-06-17 HIGH 7.5 CVE-2026-48779 ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7… Ws 5.2.5 / 6.2.4+ Fix from $1,9502026-06-17 MEDIUM 6.9 CVE-2026-27869 An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the… Mitigation only Fix from $1,6002026-06-17 CRITICAL 9.2 CVE-2026-48853 Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated … Patch available Fix from $2,3002026-06-15 HIGH 8.7 CVE-2026-48854 Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory … Patch available Fix from $1,9502026-06-15 MEDIUM 6.5 CVE-2026-8683 Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows … Mattermost Desktop after 6.1.5 Fix from $1,6002026-06-15 MEDIUM 6.5 CVE-2026-53522 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the Nezha… Mitigation only Fix from $1,6002026-06-12 MEDIUM 5.3 CVE-2026-50560 Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTT… Netty 4.1.135 / 4.2.15+ Fix from $1,6002026-06-12 HIGH 7.5 CVE-2026-50011 Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArra… Netty 4.1.135 / 4.2.15+ Fix from $1,9502026-06-12 HIGH 7.5 CVE-2026-48748 Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Final and prior to version 4.2.15… Netty 4.2.15+ Fix from $1,9502026-06-12 HIGH 7.5 CVE-2026-46340 Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final … Netty 4.1.135 / 4.2.15+ Fix from $1,9502026-06-12 HIGH 7.5 CVE-2026-45416 Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClient… Netty 4.1.135 / 4.2.15+ Fix from $1,9502026-06-12 MEDIUM 5.3 CVE-2026-49347 Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. T… Mitigation only Fix from $1,6002026-06-12 HIGH 7.5 CVE-2026-44250 Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.… Netty 4.1.135 / 4.2.15+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-44890 Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.… Netty 4.1.135 / 4.2.15+ Fix from $1,9502026-06-11 MEDIUM 6.0 CVE-2026-45802 FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2… Patch available Fix from $1,6002026-06-11 HIGH 7.5 CVE-2026-44488 Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response… Axios 1.16.0+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-7250 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un… GitLab 18.10.8 / 18.11.5+ Fix from $1,9502026-06-11 MEDIUM 6.5 CVE-2026-1500 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un… GitLab 18.10.8 / 18.11.5+ Fix from $1,6002026-06-11