Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2021-47876 GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability in the input field that allows attackers to crash the application by sending … No fix yet Fix from $1,9502026-01-21 HIGH 7.5 CVE-2021-47877 GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an over… No fix yet Fix from $1,9502026-01-21 CRITICAL 9.8 CVE-2021-47875 GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buf… Mitigation only Fix from $2,3002026-01-21 HIGH 7.5 CVE-2021-47865 ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connect… No fix yet Fix from $1,9502026-01-21 HIGH 7.4 CVE-2025-68133 EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's memory and cause the module … Everest 2025.10.0+ Fix from $1,9502026-01-21 MEDIUM 6.5 CVE-2026-21696 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1… Wings 1.12.0+ Fix from $1,6002026-01-19 MEDIUM 6.5 CVE-2025-69199 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings… Wings 1.12.0+ Fix from $1,6002026-01-19 MEDIUM 6.8 CVE-2025-11044 An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 an… Mitigation only Fix from $1,6002026-01-19 HIGH 7.5 CVE-2026-23490 pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed… Pyasn1 0.6.2+ Fix from $1,9502026-01-16 MEDIUM 6.5 CVE-2025-14435 Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticat… Mattermost Server 10.11.9 / 11.0.7+ Fix from $1,6002026-01-16 MEDIUM 6.5 CVE-2025-14822 Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU r… Mattermost Server 10.11.9+ Fix from $1,6002026-01-16 HIGH 7.5 CVE-2021-47793 Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payl… Telegram Desktop No fix yet Fix from $1,9502026-01-16 HIGH 7.5 CVE-2021-47791 SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input … Smartftp No fix yet Fix from $1,9502026-01-16 HIGH 7.5 CVE-2026-22045 Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' … Traefik 2.11.35 / 3.6.7+ Fix from $1,9502026-01-15 HIGH 7.5 CVE-2026-22803 SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4, the experimental form remote… Kit 2.49.5+ Fix from $1,9502026-01-15 HIGH 7.5 CVE-2021-47784 Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar w… No fix yet Fix from $1,9502026-01-15 MEDIUM 5.5 CVE-2021-47771 RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to crash the application. Attac… Rdp Manager No fix yet Fix from $1,6002026-01-15 HIGH 7.5 CVE-2021-47752 AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concu… Awebserver No fix yet Fix from $1,9502026-01-15 HIGH 7.5 CVE-2026-0897 Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allow… Keras after 3.13.0 Fix from $1,9502026-01-15 HIGH 7.5 CVE-2026-22917 Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service. Tdc X401gl Firmware 1.5.0+ Fix from $1,9502026-01-15 HIGH 7.5 CVE-2026-22036 Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default max… Undici 6.23.0 / 7.18.2+ Fix from $1,9502026-01-14 MEDIUM 6.5 CVE-2026-0543 Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (CAPEC-130) through a specially… Kibana 8.19.0 / 9.1.10+ Fix from $1,6002026-01-13 MEDIUM 6.5 CVE-2026-0530 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted r… Kibana 7.17.29 / 8.19.10+ Fix from $1,6002026-01-13 MEDIUM 6.5 CVE-2026-0531 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-130) via a specially crafted b… Kibana 7.17.29 / 8.19.10+ Fix from $1,6002026-01-13 HIGH 7.5 CVE-2025-37166 A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could ente… Mitigation only Fix from $1,9502026-01-13 HIGH 7.5 CVE-2024-58339 LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack Va… Llamaindex after 0.12.2 Fix from $1,9502026-01-12 HIGH 7.5 CVE-2026-22773 vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine se… Vllm 0.12.0+ Fix from $1,9502026-01-10 MEDIUM 6.5 CVE-2025-10569 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could h… GitLab 18.5.5 / 18.6.3+ Fix from $1,6002026-01-09 HIGH 7.5 CVE-2025-50334 An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting component Dnsserver 14.0+ Fix from $1,9502026-01-08 HIGH 7.5 CVE-2025-68151 CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical… Coredns 1.14.0+ Fix from $1,9502026-01-08