Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.3 CVE-2026-15144 @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can… Fastify\/rate Limit 11.2.0+ Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-54638 gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker con… No fix yet Fix from $1,9502026-07-28 HIGH 8.6 CVE-2026-54609 QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards REC… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-54332 gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads… Gopacket 1.6.1+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-54345 gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtra… Gopacket 1.6.1+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-61609 Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProv… No fix yet Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-47483 NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource co… No fix yet Fix from $1,9502026-07-28 HIGH 8.7 CVE-2026-59248 Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on … No fix yet Fix from $1,9502026-07-28 MEDIUM 6.9 CVE-2026-65624 Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connectio… No fix yet Fix from $1,6002026-07-28 MEDIUM 5.3 CVE-2026-64646 Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests target… Next.js 15.5.21 / 16.2.11+ Fix from $1,6002026-07-27 HIGH 7.5 CVE-2026-59251 Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial … Erlang\/otp 1.17.1.5 / 1.20.3.4+ Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-42792 Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminat… Erlang\/otp 15.2.7.11 / 16.4.0.4+ Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-58389 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. … Thrift 0.24.0+ Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-55968 Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue… Thrift 0.24.0+ Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-45112 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 bef… Thrift 0.24.0+ Fix from $1,9502026-07-27 MEDIUM 5.3 CVE-2026-17501 A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp … No fix yet Fix from $1,6002026-07-27 MEDIUM 5.5 CVE-2026-66037 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthe… Ffmpeg after 8.1.2 Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-25800 Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, th… No fix yet Fix from $1,9502026-07-23 HIGH 7.5 CVE-2026-16756 Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-serv… No fix yet Fix from $1,9502026-07-23 HIGH 7.5 CVE-2026-14257 brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-13074 An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the await… MongoDB No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-13075 An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusio… MongoDB No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-13076 An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data typ… MongoDB No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-13069 An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption f… MongoDB 7.0.39 / 8.0.28+ Fix from $1,6002026-07-22 HIGH 7.5 CVE-2026-11622 A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker … No fix yet Fix from $1,9502026-07-22 MEDIUM 5.3 CVE-2026-47013 Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Easily exploitable vulnerabil… Jdk No fix yet Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-42397 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An aut… Kibana 9.3.7 / 9.4.4+ Fix from $1,6002026-07-21 HIGH 7.5 CVE-2026-15957 Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS… No fix yet Fix from $1,9502026-07-21 MEDIUM 5.3 CVE-2026-59848 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing … Hardened Images No fix yet Fix from $1,6002026-07-21 HIGH 7.5 CVE-2026-55831 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTI… Netty 4.1.136 / 4.2.16+ Fix from $1,9502026-07-21