Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2025-47950 CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC… Coredns 1.12.2+ Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-22484 An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user … Mitigation only Fix from $1,9502025-06-06 HIGH 7.5 CVE-2025-29872 An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user … File Station 5.5.6.4847+ Fix from $1,9502025-06-06 MEDIUM 5.5 CVE-2025-5683 When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 throug… Qt 6.5.10 / 6.8.5+ Fix from $1,6002025-06-05 MEDIUM 5.3 CVE-2025-49007 Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.16, there is a denial of service vulnerability in the… Rack 3.1.16+ Fix from $1,6002025-06-04 HIGH 7.5 CVE-2018-25112 An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected products by creating large a… Mitigation only Fix from $1,9502025-06-04 MEDIUM 5.7 CVE-2025-49000 InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper… Inventree 0.17.13+ Fix from $1,6002025-06-03 HIGH 8.7 CVE-2025-46807 A Allocation of Resources Without Limits or Throttling vulnerability in sslh allows attackers to easily exhaust the file descriptors in sslh and deny… Mitigation only Fix from $1,9502025-06-02 MEDIUM 6.5 CVE-2025-3050 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user t… Db2 after 12.1.1 Fix from $1,6002025-05-29 MEDIUM 6.9 CVE-2025-48738 An e-mail flooding vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 before 5.5.1 allows u… Mitigation only Fix from $1,6002025-05-23 MEDIUM 5.3 CVE-2025-48375 Schule is open-source school management system software. Prior to version 1.0.1, the file forgot_password.php (or equivalent endpoint responsible for… Schule School Management System No fix yet Fix from $1,6002025-05-23 HIGH 7.5 CVE-2024-7803 An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord… GitLab 17.10.7 / 17.11.3+ Fix from $1,9502025-05-23 MEDIUM 6.5 CVE-2025-0993 An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an… GitLab 17.10.7 / 17.11.3+ Fix from $1,6002025-05-22 MEDIUM 6.5 CVE-2025-2853 An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of proper va… GitLab 17.10.7 / 17.11.3+ Fix from $1,6002025-05-22 MEDIUM 6.5 CVE-2025-3111 An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of… GitLab 17.10.7 / 17.11.3+ Fix from $1,6002025-05-22 HIGH 7.5 CVE-2025-4416 Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events L… Events Log Track 3.1.11 / 4.0.2+ Fix from $1,9502025-05-21 MEDIUM 6.5 CVE-2025-47793 Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a… Group Folders 16.0.11 / 17.0.5+ Fix from $1,6002025-05-16 HIGH 7.5 CVE-2025-47287 Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo… Debian Linux 6.5.0+ Fix from $1,9502025-05-15 MEDIUM 5.9 CVE-2025-29954 Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a netw… Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 MEDIUM 6.2 CVE-2025-29957 Uncontrolled resource consumption in Windows Deployment Services allows an unauthorized attacker to deny service locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,6002025-05-13 HIGH 7.5 CVE-2025-26677 Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. Windows Server 2016 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-3632 IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardware Security Module (HSM) due… 4769 Developers Toolkit 7.5.62+ Fix from $1,9502025-05-12 HIGH 7.5 CVE-2024-8973 An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 p… GitLab 17.9.8 / 17.10.6+ Fix from $1,9502025-05-09 MEDIUM 5.3 CVE-2025-4432 A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attack… Patch available Fix from $1,6002025-05-09 MEDIUM 5.5 CVE-2025-37805 In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitialized work_structs Betty repo… Linux Kernel 5.15.181 / 6.1.136+ Fix from $1,6002025-05-08 MEDIUM 5.3 CVE-2025-32873EPSS 14% An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerabl… Django 4.2.21 / 5.1.9+ Fix from $1,6002025-05-08 HIGH 7.5 CVE-2025-46727 Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/… Rack 2.2.14 / 3.0.16+ Fix from $1,9502025-05-07 HIGH 7.5 CVE-2025-36504 When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization… Big Ip Access Policy Manager 16.1.6 / 17.1.2+ Fix from $1,9502025-05-07 MEDIUM 6.5 CVE-2025-1000 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 could allow an authenticated user… Db2 after 12.1.1 Fix from $1,6002025-05-05 MEDIUM 6.5 CVE-2025-0915 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.1 under specific configurations c… Db2 after 12.1.1 Fix from $1,6002025-05-05