Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2025-66560 Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerabi… Quarkus 3.20.5 / 3.27.2+ Fix from $1,9502026-01-07 MEDIUM 6.5 CVE-2025-66838 In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files… Aris after 10.0.23.0.3587512 Fix from $1,6002026-01-07 MEDIUM 5.3 CVE-2025-15474 AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth L… Mitigation only Fix from $1,6002026-01-07 HIGH 7.5 CVE-2020-36907 Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unus… No fix yet Fix from $1,9502026-01-06 HIGH 7.5 CVE-2025-69228 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way… Aiohttp 3.13.3+ Fix from $1,9502026-01-06 MEDIUM 5.3 CVE-2025-69229 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result… Aiohttp 3.13.3+ Fix from $1,6002026-01-06 HIGH 7.5 CVE-2025-69223 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a Do… Aiohttp 3.13.3+ Fix from $1,9502026-01-05 CRITICAL 9.1 CVE-2025-68456 Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trig… Craft Cms 4.16.17 / 5.8.21+ Fix from $2,3002026-01-05 MEDIUM 6.5 CVE-2025-47208 An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote… Quts Hero Mitigation only Fix from $1,6002026-01-02 HIGH 7.5 CVE-2025-68272 Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 all… Signal K Server 2.19.0+ Fix from $1,9502026-01-01 HIGH 7.5 CVE-2022-50799 Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server respon… No fix yet Fix from $1,9502025-12-30 HIGH 7.5 CVE-2022-50695 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary h… Impact Firmware No fix yet Fix from $1,9502025-12-30 HIGH 7.5 CVE-2025-68148 FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy mod… Freshrss 1.28.0+ Fix from $1,9502025-12-27 HIGH 7.5 CVE-2025-11419 A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiatin… Mitigation only Fix from $1,9502025-12-23 HIGH 7.5 CVE-2021-47713 Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries … Graphql Engine No fix yet Fix from $1,9502025-12-22 MEDIUM 6.5 CVE-2025-14299 The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated atta… Tapo C200 Firmware Mitigation only Fix from $1,6002025-12-20 MEDIUM 6.5 CVE-2025-68389 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation … Kibana 8.19.9 / 9.1.9+ Fix from $1,6002025-12-18 MEDIUM 6.5 CVE-2025-68384 Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allo… Elasticsearch 8.19.9 / 9.1.9+ Fix from $1,6002025-12-18 MEDIUM 5.3 CVE-2025-68388 Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of… Packetbeat 8.19.9 / 9.1.9+ Fix from $1,6002025-12-18 MEDIUM 5.3 CVE-2025-14466 A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with networ… Mitigation only Fix from $1,6002025-12-16 HIGH 7.5 CVE-2025-68156 Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `mi… Expr 1.17.7+ Fix from $1,9502025-12-16 MEDIUM 5.3 CVE-2025-64702 quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HT… Quic Go 0.57.0+ Fix from $1,6002025-12-11 MEDIUM 6.5 CVE-2025-4097 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could… GitLab 18.4.6 / 18.5.4+ Fix from $1,6002025-12-11 HIGH 7.5 CVE-2025-12562 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could… GitLab 18.4.6 / 18.5.4+ Fix from $1,9502025-12-11 MEDIUM 6.5 CVE-2025-14157 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could h… GitLab 18.4.6 / 18.5.4+ Fix from $1,6002025-12-11 HIGH 7.5 CVE-2025-66473 XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST… Xwiki 16.10.11 / 17.4.4+ Fix from $1,9502025-12-10 HIGH 8.7 CVE-2025-9368 A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cyc… No fix yet Fix from $1,9502025-12-09 MEDIUM 6.5 CVE-2025-41694 A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more … Fl Switch 2708 Pn Firmware 3.50+ Fix from $1,6002025-12-09 MEDIUM 6.5 CVE-2025-36140 IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation o… Watsonx.data 2.2.2+ Fix from $1,6002025-12-08 MEDIUM 5.5 CVE-2025-48569 In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no… Android No fix yet Fix from $1,6002025-12-08