Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.5 CVE-2026-12570 A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the … No fix yet Fix from $4,0002026-08-10 HIGH 7.5 CVE-2026-52879 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a … No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-52880 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable de… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-46405 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, o… No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-15972 Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connecti… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-19015 Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roo… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2025-71411 Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2025-71410 Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC func… No fix yet Fix from $1,6002026-08-07 HIGH 8.7 CVE-2026-67585 Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abo… No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-54225 Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no … Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-18649 A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size … No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-71321 Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_islan… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-71314 Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island … No fix yet Fix from $1,9502026-08-05 MEDIUM 5.9 CVE-2026-71310 rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNEC… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-16100 A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account… Build Of Keycloak 26.6.5+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-59675 When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. B… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-68075 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-68078 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67553 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67555 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67591 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Protonj2 1.2.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67592 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-66275 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-66277 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67465 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Proton Dotnet 1.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67588 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-68060 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss… Qpid Broker J 10.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-68074 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Broker J 10.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-66257 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Proton J 0.35.0+ Fix from $1,9502026-08-05 HIGH 8.7 CVE-2026-68494 The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parse… No fix yet Fix from $1,9502026-08-04