Vulnerability index

Browse CVEs

63 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2026-73635 Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured, the locale used for localize… Struts Fix unknown Fix from $4,9002026-08-15 HIGH 7.5 CVE-2026-54225 Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no … Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-68078 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-68075 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67592 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-67555 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67553 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67591 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Protonj2 1.2.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-66277 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-66275 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67465 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Proton Dotnet 1.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67588 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-68060 A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss… Qpid Broker J 10.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-68074 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Broker J 10.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-66257 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af… Qpid Proton J 0.35.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-58389 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. … Thrift 0.24.0+ Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-55968 Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue… Thrift 0.24.0+ Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-45112 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 bef… Thrift 0.24.0+ Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-54428 Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl… Httpcomponents Core after 5.4.2 Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-49361 Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing un… Fluss 0.9.1+ Fix from $1,9502026-06-01 HIGH 7.5 CVE-2026-41284 Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2… Tomcat 9.0.118 / 10.1.55+ Fix from $1,9502026-05-12 MEDIUM 5.3 CVE-2025-69233 Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t… Cloudstack 4.20.3.0 / 4.22.0.1+ Fix from $1,6002026-05-08 HIGH 7.3 CVE-2026-29168 Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data. This issue affects Apache… HTTP Server 2.4.67+ Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-42440 OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3… Opennlp 2.5.9+ Fix from $1,9502026-05-04 HIGH 7.5 CVE-2026-39304 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do… Activemq 5.19.4 / 6.2.4+ Fix from $1,9502026-04-10 HIGH 7.5 CVE-2025-48976EPSS 68% Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects … Commons Fileupload 1.6+ Fix from $1,9502025-06-16 HIGH 7.5 CVE-2025-48988EPSS 57% Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7… Tomcat 9.0.106 / 10.1.42+ Fix from $1,9502025-06-16 HIGH 7.5 CVE-2024-37358 Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthent… James Server 3.7.6 / 3.8.2+ Fix from $1,9502025-02-06 HIGH 7.5 CVE-2024-38286 Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0… Tomcat 9.0.90 / 10.1.25+ Fix from $1,9502024-11-07 HIGH 7.5 CVE-2024-27316EPSS 91% HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client do… HTTP Server 2.4.59+ Fix from $1,9502024-04-04