Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.7 CVE-2026-57212 RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid J… Rabbitmq Server 4.2.5+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-59161 Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows … Excelize 2.11.0+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-54063 Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/xuri… Excelize 2.11.0+ Fix from $1,9502026-07-10 HIGH 8.7 CVE-2026-53653 Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by request… Patch available Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-58661 n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The … Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-56309 Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create public… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.9 CVE-2026-56814 Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enforce its :length budget agains… Patch available Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-40006 Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulne… Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-60108 Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthenticated remote attackers to cause… Zeek 8.0.9+ Fix from $1,9502026-07-09 MEDIUM 5.9 CVE-2026-12590 Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value suc… Body Parser 1.20.6 / 2.3.0+ Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-31984 A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size li… Cmc 26.2.0+ Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-49866 libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs an… Patch available Fix from $1,9502026-07-08 HIGH 8.2 CVE-2026-55575 LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filter at src/filters/array.ts al… Patch available Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59868 js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend quadratic CPU time parsing a … Js Yaml 5.2.0+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59870 js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src/tag/sequence/omap.ts uses om… Js Yaml 5.2.1+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-59873 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, … Tar 7.5.19+ Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-49146 App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ack searches up the directory h… Patch available Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-60000 sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) becaus… Openssh 10.4+ Fix from $1,9502026-07-08 MEDIUM 6.5 CVE-2026-60001 sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. Openssh 10.4+ Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-55078 Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.… Coder 2.29.17 / 2.32.7+ Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-55434 Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.… Coder 2.33.8 / 2.34.2+ Fix from $1,6002026-07-07 HIGH 7.5 CVE-2026-56811 Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated atta… Phoenix 1.5.15 / 1.6.17+ Fix from $1,9502026-07-07 MEDIUM 6.5 CVE-2026-41899 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has n… Patch available Fix from $1,6002026-07-06 MEDIUM 6.5 CVE-2026-55646 vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions and /v1/audio/translations rou… Vllm 0.24.0+ Fix from $1,6002026-07-06 HIGH 7.5 CVE-2026-13698 A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-cry… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-06 HIGH 8.7 CVE-2026-56810 Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a denial of service via an oversize… Patch available Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-11586 By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a… Curl 8.21.0+ Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-58465 Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that … Patch available Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-11946 An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpoin… Patch available Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-9563 In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of charact… Patch available Fix from $1,9502026-07-02