Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.1 CVE-2026-44931 The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-serv… Mitigation only Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-8202 Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user w… MongoDB 7.0.34 / 8.0.23+ Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-40863 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML … Phpspreadsheet 1.30.4 / 2.1.16+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-40902 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's … Phpspreadsheet 1.30.4 / 2.1.16+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-44240 basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel mul… Mitigation only Fix from $1,9502026-05-12 MEDIUM 5.5 CVE-2026-42444 NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem ima… Nanazip 6.0.1698.0+ Fix from $1,6002026-05-12 HIGH 7.5 CVE-2026-23826 A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerabilit… Arubaos 8.10.0.22 / 8.12.0.7+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-41284 Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2… Tomcat 9.0.118 / 10.1.55+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-22925 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when sub… Simatic Cn 4100 Firmware 5.0+ Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-42256 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.… Net\ 0.4.24 / 0.5.14+ Fix from $1,6002026-05-09 HIGH 7.5 CVE-2026-42294 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, … Argo Workflows 3.7.14 / 4.0.5+ Fix from $1,9502026-05-09 HIGH 7.5 CVE-2026-42189 Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's key… Russh 0.23.1 / 0.60.1+ Fix from $1,9502026-05-08 HIGH 8.7 CVE-2026-44499 ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeli… Mitigation only Fix from $1,9502026-05-08 HIGH 7.5 CVE-2026-42793 Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via atom tab… Absinthe 1.10.2+ Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2026-44500 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version… Zebra Chain 4.4.0 / 6.0.0+ Fix from $1,6002026-05-08 HIGH 7.8 CVE-2026-43329 In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: strictly check for maximum number of actions The maximum … Linux Kernel 5.15.203 / 6.1.168+ Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2025-69233 Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t… Cloudstack 4.20.3.0 / 4.22.0.1+ Fix from $1,6002026-05-08 MEDIUM 5.5 CVE-2026-8124 A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. T… Gpac after 26.02.0 Fix from $1,6002026-05-08 HIGH 7.5 CVE-2026-7541 A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by … Enterprise Server 3.16.18 / 3.17.15+ Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-39820 Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. Go 1.25.10 / 1.26.3+ Fix from $1,9502026-05-07 MEDIUM 5.0 CVE-2026-41648 Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML f… Incus 7.0.0+ Fix from $1,6002026-05-07 HIGH 8.3 CVE-2025-14341 Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in… Mitigation only Fix from $1,9502026-05-07 HIGH 7.1 CVE-2026-41644 monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) vulnerability in monetr's Lun… Monetr 1.12.5+ Fix from $1,9502026-05-07 MEDIUM 5.9 CVE-2026-41484 OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, whe… Opentelemetry.exporter.onecollector after 1.15.0 Fix from $1,6002026-05-06 MEDIUM 5.3 CVE-2026-41310 OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cach… Opentelemetry.exporter.zipkin 1.15.3+ Fix from $1,6002026-05-06 MEDIUM 5.9 CVE-2026-41483 OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequest… Opentelemetry.resources.azure after 1.15.0 Fix from $1,6002026-05-06 MEDIUM 5.3 CVE-2026-6860 A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if… Vert.x after 5.0.11 Fix from $1,6002026-05-06 HIGH 7.5 CVE-2026-32934 CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and m… Coredns 1.14.3+ Fix from $1,9502026-05-05 HIGH 8.7 CVE-2026-32689 Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport… Patch available Fix from $1,9502026-05-05 HIGH 7.5 CVE-2025-66369 An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 24… Mitigation only Fix from $1,9502026-05-05