Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.3 CVE-2026-29168 Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache… HTTP Server 2.4.67+ Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-42437 OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSocket path that accepts oversize… Patch available Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-7776 Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS ha… Mitigation only Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-7768 @fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote … Fastify\/accepts Serializer 6.0.4+ Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-42236 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accept… N8n 1.123.32+ Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-42154 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) … Prometheus 3.5.3 / 3.11.3+ Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-42440 OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3… Opennlp 2.5.9+ Fix from $1,9502026-05-04 MEDIUM 5.9 CVE-2025-70071 An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray() Mitigation only Fix from $1,6002026-05-04 HIGH 7.5 CVE-2025-70069 An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp and ConvertMeshMultiMaterial() method Mitigation only Fix from $1,9502026-05-04 HIGH 8.7 CVE-2026-42786 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhau… Patch available Fix from $1,9502026-05-01 MEDIUM 6.9 CVE-2026-42788 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhaustion via oversized HTTP/2 fr… Patch available Fix from $1,6002026-05-01 HIGH 8.2 CVE-2026-39804 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhau… Patch available Fix from $1,9502026-05-01 HIGH 7.5 CVE-2026-43507 An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused b… Prosody 0.12.6 / 13.0.5+ Fix from $1,9502026-05-01 MEDIUM 6.5 CVE-2025-36122 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user … Db2 after 12.1.3 Fix from $1,6002026-04-30 HIGH 7.5 CVE-2025-51846 CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users … Cryptpad 2026.2.2+ Fix from $1,9502026-04-30 HIGH 7.5 CVE-2026-42198 pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of servi… Postgresql Jdbc Driver 42.7.11+ Fix from $1,9502026-04-29 MEDIUM 6.5 CVE-2026-42420 OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attacke… Openclaw 2026.4.8+ Fix from $1,6002026-04-28 MEDIUM 6.5 CVE-2026-41408 OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and … Openclaw 2026.3.31+ Fix from $1,6002026-04-28 HIGH 7.5 CVE-2026-41399 OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. Unauthenticat… Openclaw 2026.3.28+ Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-41400 OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start val… Openclaw 2026.3.31+ Fix from $1,9502026-04-28 HIGH 7.5 CVE-2026-32688 Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via ato… Plug.cowboy 2.8.1+ Fix from $1,9502026-04-27 MEDIUM 5.3 CVE-2026-42034 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed wh… Axios 0.31.1 / 1.15.1+ Fix from $1,6002026-04-24 MEDIUM 5.3 CVE-2026-42036 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the … Axios 0.31.1 / 1.15.1+ Fix from $1,6002026-04-24 HIGH 7.5 CVE-2026-42039 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no dep… Axios 0.31.1 / 1.15.1+ Fix from $1,9502026-04-24 HIGH 7.5 CVE-2026-21728 Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment stra… Tempo 2.8.4 / 2.9.2+ Fix from $1,9502026-04-24 HIGH 7.5 CVE-2026-41324 basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing … Basic Ftp 5.3.0+ Fix from $1,9502026-04-24 HIGH 8.2 CVE-2026-41309 Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaus… Patch available Fix from $1,9502026-04-24 MEDIUM 5.9 CVE-2026-41173 The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0.1.0-alpha.8, OpenTelemetry.S… Patch available Fix from $1,6002026-04-23 MEDIUM 5.9 CVE-2026-41078 OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure wh… Opentelemetry 1.6.0+ Fix from $1,6002026-04-23 MEDIUM 5.3 CVE-2026-34062 nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_t… Nimiq Proof Of Stake 1.3.0+ Fix from $1,6002026-04-22