Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.3 CVE-2026-53596 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does … No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-48824 Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a de… Mailpit 1.30.1+ Fix from $1,6002026-07-20 MEDIUM 5.9 CVE-2026-45712 Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-leve… Mailpit 1.30.0+ Fix from $1,6002026-07-20 HIGH 7.5 CVE-2026-45713 Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that control… Mailpit 1.30.0+ Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-63750 SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket connections, allowing attacker… Surrealdb 3.1.0+ Fix from $1,9502026-07-20 MEDIUM 5.3 CVE-2026-15588 A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2025-71396 SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting f… Surrealdb 2.0.5 / 2.1.5+ Fix from $1,6002026-07-18 MEDIUM 6.3 CVE-2026-54490 websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a… No fix yet Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-50271 Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming… No fix yet Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-50272 dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/s… No fix yet Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-50274 Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datado… No fix yet Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-44891 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.c… Netty 4.1.136 / 4.2.16+ Fix from $1,9502026-07-17 MEDIUM 6.5 CVE-2026-55254 NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCalc.Core/Helpers/MathHelpe… Ncalc Fix unknown Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-54463 websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver inc… Websocket Driver 0.8.1+ Fix from $1,9502026-07-17 MEDIUM 6.3 CVE-2026-54464 ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages th… No fix yet Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-54465 websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on… Websocket Driver 0.8.1+ Fix from $1,9502026-07-17 MEDIUM 5.3 CVE-2026-48504 OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did … No fix yet Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-49835 Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request… Sigstore Timestamp Authority 2.1.0+ Fix from $1,9502026-07-17 MEDIUM 6.5 CVE-2026-47184 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record int… Zeroconf No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-48045 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained every tr… Zeroconf No fix yet Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-50273 Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage … No fix yet Fix from $1,9502026-07-17 MEDIUM 6.5 CVE-2026-49209 Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__inv… Ux 2.36.0+ Fix from $1,6002026-07-17 MEDIUM 5.7 CVE-2026-15007 A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supply… No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-62210 OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gatewa… Openclaw 2026.6.1+ Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-54340 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combin… H2o 2026-06-04+ Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-44453 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when cal… H2o 2026-05-29+ Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-44433 Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer co… Quicly 2026-05-29+ Fix from $1,9502026-07-16 MEDIUM 6.3 CVE-2026-55407 Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the decode_unknown_field function in… No fix yet Fix from $1,6002026-07-16 HIGH 7.5 CVE-2026-21729 Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strat… No fix yet Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-23538 A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket conne… No fix yet Fix from $1,9502026-07-16