Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 6.5 CVE-2026-49089 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query … No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-17199 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation. I No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-73565 @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route w… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-42931 Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-70464 rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection … No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-70455 rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt sh… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-14456 Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can … No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-48702 Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/t… No fix yet Fix from $4,9002026-08-13 HIGH 8.7 CVE-2026-73500 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can r… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-73493 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregate… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-71469 A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique tok… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-63299 An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail… No fix yet Fix from $5,7502026-08-12 MEDIUM 5.3 CVE-2026-7427 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under … No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-17271 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size. I after 7.6 Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-71408 A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 a… No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2025-41770 An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt acc… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-63133 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-48804 python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` me… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-73228 Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py … No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-48802 python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation o… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-48809 python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of … No fix yet Fix from $4,9002026-08-11 HIGH 8.2 CVE-2026-73214 Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-73089 Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains ever… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-54113 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-15561 A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthentica… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-19517 Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlot… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.9 CVE-2026-58238 SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-72914 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative stat… No fix yet Fix from $4,9002026-08-10 HIGH 7.5 CVE-2026-18618 A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service … No fix yet Fix from $4,9002026-08-10 HIGH 8.7 CVE-2025-15682 TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can… No fix yet Fix from $4,9002026-08-10