Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2026-33232 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6… Mitigation only Fix from $1,9502026-05-19 MEDIUM 6.5 CVE-2026-2325 Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpo… Mattermost Server 10.11.14 / 11.4.4+ Fix from $1,6002026-05-18 HIGH 7.5 CVE-2021-47959 WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by send… No fix yet Fix from $1,9502026-05-15 MEDIUM 6.9 CVE-2026-44679 Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly tri… Mitigation only Fix from $1,6002026-05-14 HIGH 7.5 CVE-2026-44216 Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained check… Wasmtime 36.0.8 / 43.0.2+ Fix from $1,9502026-05-14 HIGH 8.2 CVE-2026-8468 Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in… Patch available Fix from $1,9502026-05-14 MEDIUM 6.5 CVE-2026-8280 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou… GitLab 18.9.7 / 18.10.6+ Fix from $1,6002026-05-14 HIGH 7.5 CVE-2026-1659 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou… GitLab 18.9.7 / 18.10.6+ Fix from $1,9502026-05-14 HIGH 7.5 CVE-2025-14870 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that co… GitLab 18.9.7 / 18.10.6+ Fix from $1,9502026-05-14 HIGH 7.5 CVE-2026-42561 Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart par… No fix yet Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-28383 A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authentic… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-28376 The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leadin… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 HIGH 8.2 CVE-2026-8466 Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in … Patch available Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-44248 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section i… Netty 4.1.133 / 4.2.13+ Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-42587 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxA… Netty 4.1.133 / 4.2.13+ Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-42582 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of i… Netty 4.2.13+ Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-42583 Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of… Netty 4.1.133 / 4.2.13+ Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-44579 Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering th… Next.js 15.5.16 / 16.2.5+ Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-44004 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory direc… Vm2 3.11.0+ Fix from $1,9502026-05-13 MEDIUM 5.9 CVE-2026-44577 Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the d… Next.js 15.5.16 / 16.2.5+ Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-41227 On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in memory consumption causing the T… Big Ip Advanced Web Application Firewall after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-40629 When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  No… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 HIGH 7.5 CVE-2026-40423 When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: So… Big Ip Access Policy Manager after 17.5.1 Fix from $1,9502026-05-13 MEDIUM 5.5 CVE-2025-32425 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. In A… Autogpt Platform 0.6.32+ Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-39803 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhau… Bandit 1.11.1+ Fix from $1,9502026-05-13 MEDIUM 5.1 CVE-2026-44931 The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-serv… Mitigation only Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-8202 Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user w… MongoDB 7.0.34 / 8.0.23+ Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-40863 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML … Phpspreadsheet 1.30.4 / 2.1.16+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-40902 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's … Phpspreadsheet 1.30.4 / 2.1.16+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-44240 basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel mul… Mitigation only Fix from $1,9502026-05-12