Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2026-27571 NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles comp… Nats Server 2.11.12 / 2.12.3+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-25985 ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SV… Imagemagick 6.9.13-40 / 7.1.2-15+ Fix from $1,9502026-02-24 HIGH 7.5 CVE-2026-27729 Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit, which can lead to memory exh… \@astrojs\/node 9.5.4+ Fix from $1,9502026-02-24 MEDIUM 6.5 CVE-2026-26047 A denial-of-service vulnerability was identified in Moodle’s TeX formula editor. When rendering TeX content using mimetex, insufficient execution tim… Moodle 4.5.9 / 5.0.5+ Fix from $1,6002026-02-21 MEDIUM 5.5 CVE-2026-27026 pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to long … Pypdf 6.7.1+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-26312 Stalwart is a mail and collaboration server. A denial-of-service vulnerability exists in Stalwart Mail Server versions 0.13.0 through 0.15.4 where ac… Stalwart 0.15.5+ Fix from $1,6002026-02-19 HIGH 7.5 CVE-2026-26313 go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can cause high memory us… Go Ethereum 1.17.0+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2026-25535 jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` method results in denial of s… Jspdf 4.2.0+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2019-25350 XMedia Recode 3.4.8.6 contains a denial of service vulnerability that allows attackers to crash the application by loading a specially crafted .m3u p… No fix yet Fix from $1,9502026-02-18 MEDIUM 5.5 CVE-2025-14876 A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length limit in the AKCIPHER path, lea… Mitigation only Fix from $1,6002026-02-18 HIGH 7.5 CVE-2019-25342 Centova Cast 3.2.12 contains a denial of service vulnerability that allows attackers to overwhelm the system by repeatedly calling the database expor… No fix yet Fix from $1,9502026-02-12 HIGH 7.5 CVE-2026-26076 ntpd-rs is a full-featured implementation of the Network Time Protocol. Prior to 1.7.1, an attacker can remotely induce moderate increases (2-4 times… Ntpd Rs 1.7.1+ Fix from $1,9502026-02-12 HIGH 7.5 CVE-2026-25949 Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unau… Traefik 3.6.8+ Fix from $1,9502026-02-12 HIGH 7.5 CVE-2026-21434 webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive memory consumption in webtran… Webtransport Go 0.10.0+ Fix from $1,9502026-02-12 MEDIUM 5.5 CVE-2026-20608 This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.… Safari 18.7.5 / 26.3+ Fix from $1,6002026-02-11 HIGH 7.5 CVE-2026-1837 A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninit… Libjxl after 0.11.1 Fix from $1,9502026-02-11 MEDIUM 6.5 CVE-2025-57708 An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-54149 An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-54150 An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 5.5 CVE-2025-54151 An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a local attacker gains a user account, they can then… Qsync Central 5.0.0.4+ Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2026-1387 GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could hav… GitLab 18.6.6 / 18.7.4+ Fix from $1,6002026-02-11 HIGH 7.5 CVE-2026-1456 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unau… GitLab 18.7.4 / 18.8.4+ Fix from $1,9502026-02-11 HIGH 7.5 CVE-2026-1458 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under … GitLab 18.6.6 / 18.7.4+ Fix from $1,9502026-02-11 HIGH 7.5 CVE-2025-8099 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under… GitLab 18.6.6 / 18.7.4+ Fix from $1,9502026-02-11 HIGH 7.1 CVE-2021-26381 Improper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping operations on a large number… Mitigation only Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-1847 Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the oplog from the primary. This c… MongoDB 7.0.29 / 8.0.18+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-1848 Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connect… MongoDB 7.0.29 / 8.0.18+ Fix from $1,9502026-02-10 HIGH 7.5 CVE-2026-1850 Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash. MongoDB 8.0.18 / 8.2.4+ Fix from $1,9502026-02-10 HIGH 7.7 CVE-2026-23689 Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network acc… Advanced Planning And Optimization Mitigation only Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2025-15317 Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server. Server 7.4.6.1154 / 7.5.6.1164+ Fix from $1,6002026-02-09