Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 6.5 CVE-2025-30261 An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac… Qsync Central Mitigation only Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-29890 An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a… File Station 5.5.6.4907+ Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-29898 An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can the… Qsync Central 4.5.0.7+ Fix from $1,6002025-08-29 MEDIUM 5.3 CVE-2025-58058 xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-enco… Patch available Fix from $1,6002025-08-28 HIGH 7.5 CVE-2025-6203 A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory… Vault 1.16.27 / 1.18.15+ Fix from $1,9502025-08-28 MEDIUM 6.5 CVE-2025-3601 An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could ha… GitLab 18.1.5 / 18.2.5+ Fix from $1,6002025-08-27 HIGH 7.5 CVE-2025-4225 An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that und… GitLab 18.1.5 / 18.2.5+ Fix from $1,9502025-08-27 HIGH 7.5 CVE-2025-57810 jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage method results in CPU utilizati… Jspdf 3.0.2+ Fix from $1,9502025-08-26 MEDIUM 6.5 CVE-2025-43762 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.… Digital Experience Platform 2024.Q1.15 / 2025.Q1.2+ Fix from $1,6002025-08-22 MEDIUM 6.5 CVE-2025-43752 Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.… Digital Experience Platform 2024.Q1.16 / 2025.Q1.5+ Fix from $1,6002025-08-22 MEDIUM 5.7 CVE-2025-4437 There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-… Mitigation only Fix from $1,6002025-08-20 HIGH 7.5 CVE-2025-36047 IBM WebSphere Application Server Liberty 18.0.0.2 through 25.0.0.8 is vulnerable to a denial of service, caused by sending a specially-crafted reques… Websphere Application Server 25.0.0.9+ Fix from $1,9502025-08-14 MEDIUM 6.5 CVE-2025-55199 Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, it is possible to craft a JSON Schema file in a manner which could caus… Helm 3.18.5+ Fix from $1,6002025-08-14 HIGH 7.5 CVE-2025-55197 pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads to the RAM being exhausted. … Pypdf 6.0.0+ Fix from $1,9502025-08-13 MEDIUM 6.5 CVE-2025-2614 An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could ha… GitLab 18.0.6 / 18.1.4+ Fix from $1,6002025-08-13 HIGH 7.5 CVE-2025-1477 An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could ha… GitLab 18.0.6 / 18.1.4+ Fix from $1,9502025-08-13 HIGH 7.5 CVE-2025-55163 Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYou… Netty 4.1.124 / 4.2.4+ Fix from $1,9502025-08-13 MEDIUM 5.3 CVE-2025-54500 An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams… Big Ip Access Policy Manager 15.1.10.8 / 16.1.6.1+ Fix from $1,6002025-08-13 MEDIUM 6.3 CVE-2025-8916 Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of… Mitigation only Fix from $1,6002025-08-13 MEDIUM 6.5 CVE-2025-50172 Allocation of resources without limits or throttling in Windows DirectX allows an authorized attacker to deny service over a network. Windows 10 1809 10.0.17763.7678 / 10.0.19044.6216+ Fix from $1,6002025-08-12 MEDIUM 6.3 CVE-2025-8885 Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of… Mitigation only Fix from $1,6002025-08-12 HIGH 8.7 CVE-2025-54884 Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and… Patch available Fix from $1,9502025-08-06 MEDIUM 6.0 CVE-2025-54869 FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. In versions 2.6.2 … Patch available Fix from $1,6002025-08-06 HIGH 7.5 CVE-2025-54879 Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versi… Mastodon 4.2.24 / 4.3.11+ Fix from $1,9502025-08-06 MEDIUM 5.9 CVE-2025-8537 A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetData… Bento4 after 1.6.0-641 Fix from $1,6002025-08-05 MEDIUM 5.5 CVE-2025-48074 OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In v… Openexr No fix yet Fix from $1,6002025-08-01 HIGH 7.5 CVE-2025-54939 LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak. Litespeed Web Adc 1.8.4 / 3.3.1+ Fix from $1,9502025-08-01 HIGH 7.5 CVE-2025-2813 An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80. Mitigation only Fix from $1,9502025-07-31 MEDIUM 5.3 CVE-2025-54575 ImageSharp is a 2D graphics library. In versions below 2.1.11 and 3.0.0 through 3.1.10, a specially crafted GIF file containing a malformed comment e… Patch available Fix from $1,6002025-07-30 MEDIUM 6.9 CVE-2025-54572 The Ruby SAML library is for implementing the client side of a SAML authorization. In versions 1.18.0 and below, a denial-of-service vulnerability ex… Patch available Fix from $1,6002025-07-30