Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 6.5 CVE-2026-67199 Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.9 CVE-2026-18401 The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-69152 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() doe… Brace Expansion 1.1.18 / 2.1.4+ Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-69079 CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a … No fix yet Fix from $1,9502026-08-03 MEDIUM 5.3 CVE-2026-13586 In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-58063 In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for … No fix yet Fix from $1,6002026-08-03 MEDIUM 6.5 CVE-2026-20482 In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.9 CVE-2026-59647 In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS be… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.9 CVE-2026-59648 In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java L… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-15055 In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.9 CVE-2025-71401 better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An … No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-55733 Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-control… Guardian 2.4.1+ Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-55734 Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via… Guardian 2.4.1+ Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-54894 Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influen… Guardian 2.4.1+ Fix from $1,9502026-08-01 MEDIUM 5.3 CVE-2026-67353 guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields w… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67317 axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length ca… No fix yet Fix from $1,6002026-08-01 HIGH 7.5 CVE-2026-67297 FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body()… No fix yet Fix from $1,9502026-08-01 MEDIUM 6.5 CVE-2026-55497 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed fil… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-14539 An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows… Mcp Toolbox For Databases 1.5.0+ Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-12733 IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations. Datapower Gateway 10.5.0.22 / 10.6.0.10+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-16308 IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial… No fix yet Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-11897 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted requ… Websphere Application Server 26.0.0.8+ Fix from $1,9502026-07-30 MEDIUM 5.9 CVE-2026-16971 The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks. No fix yet Fix from $1,6002026-07-30 MEDIUM 5.9 CVE-2026-18362 The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks. No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-67437 OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_au… No fix yet Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-67432 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-67430 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.2 CVE-2026-63119 MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MC… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-15975 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under … GitLab 19.0.5 / 19.1.3+ Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-59899 Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the sup… Netty 4.1.136 / 4.2.16+ Fix from $1,9502026-07-29