Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.9 CVE-2026-53423 Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service … Patch available Fix from $1,6002026-06-11 HIGH 7.5 CVE-2026-5497 vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the … Vllm 0.19.0+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-53460 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing ch… Imagemagick 6.9.13-50 / 7.1.2-25+ Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-46673 Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsa… Mitigation only Fix from $1,9502026-06-10 HIGH 7.5 CVE-2026-46702 Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabled, russh accepted compressed… No fix yet Fix from $1,9502026-06-10 MEDIUM 5.3 CVE-2026-45664 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a… Imagemagick 6.9.13-47 / 7.1.2-22+ Fix from $1,6002026-06-10 MEDIUM 5.3 CVE-2026-45031 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a mis… Imagemagick 6.9.13-47 / 7.1.2-22+ Fix from $1,6002026-06-10 MEDIUM 5.3 CVE-2026-10740 Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of s… Mitigation only Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-24720 An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a… File Station 5.5.6.5243+ Fix from $1,6002026-06-10 MEDIUM 6.5 CVE-2026-41726 When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spr… Spring For Apache Kafka 2.8.12 / 2.9.14+ Fix from $1,6002026-06-10 HIGH 7.5 CVE-2026-41716 Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion throug… Spring Data Commons 2.7.20 / 3.3.17+ Fix from $1,9502026-06-10 MEDIUM 5.5 CVE-2026-28237 Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability. Uprof 5.3.518+ Fix from $1,6002026-06-09 MEDIUM 5.3 CVE-2026-49955 Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service ava… Patch available Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-45591 Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. Asp.net Core 8.0.28 / 9.0.17+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-42570 Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to be… Devalue 5.8.1+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-41851 Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the ev… Spring Framework 5.3.49 / 6.1.28+ Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-41007 Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HAT… Spring Hateoas 1.5.7 / 2.3.5+ Fix from $1,9502026-06-09 MEDIUM 5.9 CVE-2026-41710 An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache.… No fix yet Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-40983 In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition. Affected ver… Mitigation only Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-40984 In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Affected ver… Mitigation only Fix from $1,9502026-06-09 HIGH 7.5 CVE-2026-43973 Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded H… Gun Patch available Fix from $1,9502026-06-08 HIGH 7.5 CVE-2026-45290 Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` i… Mitigation only Fix from $1,9502026-06-05 HIGH 7.5 CVE-2026-50589 In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s… Ironic 37.0.0+ Fix from $1,9502026-06-05 MEDIUM 6.5 CVE-2026-36499 A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an exce… Mitigation only Fix from $1,6002026-06-04 HIGH 7.5 CVE-2026-40898 quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP… Quic Go 0.59.1+ Fix from $1,9502026-06-04 HIGH 7.5 CVE-2025-46638 Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially… Mitigation only Fix from $1,9502026-06-04 HIGH 7.5 CVE-2026-44545 daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both va… Daphne 4.2.2+ Fix from $1,9502026-06-03 MEDIUM 5.9 CVE-2026-48597 Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.… Tesla Patch available Fix from $1,6002026-06-02 HIGH 7.5 CVE-2026-34077 React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is… React Router 3.0.0 / 7.14.0+ Fix from $1,9502026-06-02 HIGH 7.5 CVE-2026-28299 SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to … Web Help Desk 2026.2+ Fix from $1,9502026-06-02