Vulnerability index

Browse CVEs

2,036 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2026-33592 An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersR… Patch available Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-54428 Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl… Httpcomponents Core after 5.4.2 Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-56150 Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). … Fleet Server 8.19.11 / 9.2.5+ Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-49087 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An aut… Kibana 8.19.15 / 9.3.4+ Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-20216 A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affe… Secure Endpoint 1.4.5 / 1.5.3+ Fix from $1,9502026-07-01 MEDIUM 5.5 CVE-2026-14330 Multiple unbounded alloca() calls in the PulseAudio protocol server. Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-57080 Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framin… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.3 CVE-2026-12818 Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP … Mitigation only Fix from $2,3002026-06-30 HIGH 8.2 CVE-2026-53426 Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a {:… Patch available Fix from $1,9502026-06-29 MEDIUM 5.3 CVE-2025-32394 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is … Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2025-32423 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is … Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-48933 A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affe… Node.js Patch available Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-54037 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-7105 added forkIpLimiter and for… Librechat after 0.8.3 Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-54448 Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker reads each entry with io.ReadAll(… Trivy 0.71.0+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-54024 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-11171 (commit bb58a2d0) added li… Librechat after 0.8.3 Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-40211 An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will … Mitigation only Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-12760 A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fra… Tapo C200 Firmware Mitigation only Fix from $1,6002026-06-24 HIGH 7.5 CVE-2026-49851 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (app… Mitigation only Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-54297 Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday:… Faraday 1.10.6 / 2.14.3+ Fix from $1,9502026-06-24 HIGH 8.2 CVE-2026-11972 When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive par… Patch available Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-46551 NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, the uploadViaURL path in the v1/v2 attachment API did not enforce NC_A… Mitigation only Fix from $1,6002026-06-23 HIGH 7.5 CVE-2025-61028 An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st… Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2023-54365 Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard libr… Go 1.20.10 / 1.21.3+ Fix from $1,9502026-06-23 HIGH 8.2 CVE-2026-56324 Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by ro… Mitigation only Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-48514 MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserialize reads an attacker-controlle… Messagepack 2.5.301 / 3.1.7+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-48515 MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensional array formatters read dimen… Messagepack 2.5.301 / 3.1.7+ Fix from $1,9502026-06-22 HIGH 7.5 CVE-2026-48510 MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray pay… Messagepack 2.5.301 / 3.1.7+ Fix from $1,9502026-06-22 MEDIUM 6.5 CVE-2026-39904 Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uplo… Mitigation only Fix from $1,6002026-06-22 MEDIUM 5.3 CVE-2026-54285 opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetry/core does not enforce size … Mitigation only Fix from $1,6002026-06-22 HIGH 7.5 CVE-2026-54277 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypass the max_line_size check in … Aiohttp 3.14.1+ Fix from $1,9502026-06-22