Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 8.2 CVE-2026-48862 Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in… Patch available Fix from $1,9502026-06-02 HIGH 8.2 CVE-2026-49754 Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in… Patch available Fix from $1,9502026-06-02 MEDIUM 5.5 CVE-2026-45682 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcur… Ebpf Instrumentation 0.9.0+ Fix from $1,6002026-06-02 MEDIUM 5.3 CVE-2026-45554 NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-pa… Mitigation only Fix from $1,6002026-06-02 MEDIUM 6.5 CVE-2026-40990 OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud… Spring Cloud Function 3.2.16 / 4.1.10+ Fix from $1,6002026-06-01 MEDIUM 5.0 CVE-2026-10533 A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernet… Openshift Container Platform Mitigation only Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-49361 Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un… Fluss 0.9.1+ Fix from $1,9502026-06-01 MEDIUM 5.7 CVE-2026-48187 An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the… Otrs 2026.4.1+ Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-46599 The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image … Mitigation only Fix from $1,9502026-05-29 HIGH 7.5 CVE-2026-45352 cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding c… Cpp Httplib 0.43.4+ Fix from $1,9502026-05-29 HIGH 8.6 CVE-2026-44697 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in B… Mitigation only Fix from $1,9502026-05-29 MEDIUM 5.4 CVE-2026-45023 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api… Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-45292 opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. P… Patch available Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2026-45078 Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of… Synapse 1.152.1+ Fix from $1,6002026-05-28 MEDIUM 5.5 CVE-2026-48735 pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to larg… Pypdf 6.12.1+ Fix from $1,6002026-05-28 HIGH 7.4 CVE-2026-44247 Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size li… Volcano 1.12.4 / 1.13.3+ Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-1402 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that und… GitLab 18.10.7 / 18.11.4+ Fix from $1,6002026-05-27 MEDIUM 5.5 CVE-2026-6053 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range partit… Db2 after 12.1.4 Fix from $1,6002026-05-27 HIGH 7.5 CVE-2026-1718 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transact… Db2 after 12.1.4 Fix from $1,9502026-05-27 HIGH 7.5 CVE-2025-11482 An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may … Mitigation only Fix from $1,9502026-05-26 HIGH 7.5 CVE-2026-47067 Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts… Hackney 4.0.1+ Fix from $1,9502026-05-25 MEDIUM 5.9 CVE-2026-42626 HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unaut… Mitigation only Fix from $1,6002026-05-22 HIGH 7.5 CVE-2026-8486 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit… Moveit Automation 2025.0.11 / 2025.1.7+ Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-8488 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue af… Moveit Automation 2025.0.11 / 2025.1.7+ Fix from $1,9502026-05-20 HIGH 8.2 CVE-2026-8469 Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BE… Patch available Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-3039 BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving an… Bind 9.18.49 / 9.20.23+ Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-9064 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of cont… Directory Server Mitigation only Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-41292 NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS… Unbound 1.25.1+ Fix from $1,9502026-05-20 MEDIUM 5.5 CVE-2025-57798 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.14 and prior contain a Denial … Patch available Fix from $1,6002026-05-19 MEDIUM 5.8 CVE-2026-45557 Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a … Mitigation only Fix from $1,6002026-05-19