Total
2764 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-47270 | 2026-02-06 | N/A | 7.5 HIGH | ||
|
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. The `nimiq-network-libp2p` subcrate of nimiq/core-rs-albatross is vulnerable to a Denial of Service (DoS) attack due to uncontrolled memory allocation. Specifically, the implementation of the `Discovery` network message handling allocates a buffer based on a length value provided by the peer, without enforcing an upper bound. Since this length is a `u32`, a peer can t ...
Show More |
|||||
| CVE-2026-21452 | 1 Msgpack | 1 Messagepack | 2026-02-05 | N/A | 7.5 HIGH |
|
MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later trusts the declared EXT payload length when materializing the extension data. When ExtensionValue.getData() is invoked, the library attempts to allocate a byte array of the declared length without enforc ...
Show More |
|||||
| CVE-2026-23842 | 1 Chatterbot | 1 Chatterbot | 2026-02-05 | N/A | 7.5 HIGH |
|
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. ChatterBot versions up to 1.2.10 are vulnerable to a denial-of-service condition caused by improper database session and connection pool management. Concurrent invocations of the get_response() method can exhaust the underlying SQLAlchemy connection pool, resulting in persistent service unavailability and requiring a manual restart to recover. Version 1.2.11 fixes the issue.
|
|||||
| CVE-2025-59439 | 1 Samsung | 18 Exynos 1080, Exynos 1080 Firmware, Exynos 850 and 15 more | 2026-02-05 | N/A | 7.5 HIGH |
|
An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920, W930, W1000 and Modem 5123. Incorrect handling of NAS Registration messages leads to a Denial of Service because of Improper Handling of Exceptional Conditions.
|
|||||
| CVE-2025-60753 | 1 Libarchive | 1 Libarchive | 2026-02-04 | N/A | 5.5 MEDIUM |
|
An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash).
|
|||||
| CVE-2025-63560 | 1 Kiloview | 2 E3, E3 Firmware | 2026-02-04 | N/A | 7.5 HIGH |
|
An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component.
|
|||||
| CVE-2025-6075 | 1 Python | 1 Python | 2026-02-04 | N/A | 5.5 MEDIUM |
|
If the value passed to os.path.expandvars() is user-controlled a
performance degradation is possible when expanding environment
variables.
|
|||||
| CVE-2025-65886 | 1 Oneflow | 1 Oneflow | 2026-02-03 | N/A | 7.5 HIGH |
|
A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes.
|
|||||
| CVE-2025-65888 | 1 Oneflow | 1 Oneflow | 2026-02-03 | N/A | 7.5 HIGH |
|
A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or excessively large dimension value.
|
|||||
| CVE-2025-65889 | 1 Oneflow | 1 Oneflow | 2026-02-03 | N/A | 7.5 HIGH |
|
A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
|
|||||
| CVE-2025-65890 | 1 Oneflow | 1 Oneflow | 2026-02-03 | N/A | 7.5 HIGH |
|
A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device index.
|
|||||
| CVE-2025-65891 | 1 Oneflow | 1 Oneflow | 2026-02-03 | N/A | 7.5 HIGH |
|
A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties() with an invalid or negative device index.
|
|||||
| CVE-2025-70999 | 1 Oneflow | 1 Oneflow | 2026-02-03 | N/A | 7.5 HIGH |
|
A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted device ID.
|
|||||
| CVE-2025-71000 | 1 Oneflow | 1 Oneflow | 2026-02-03 | N/A | 7.5 HIGH |
|
An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
|
|||||
| CVE-2025-30160 | 1 Redlib | 1 Redlib | 2026-02-03 | N/A | 7.5 HIGH |
|
Redlib is an alternative private front-end to Reddit. A vulnerability has been identified in Redlib where an attacker can cause a denial-of-service (DOS) condition by submitting a specially crafted base2048-encoded DEFLATE decompression bomb to the restore_preferences form. This leads to excessive memory consumption and potential system instability, which can be exploited to disrupt Redlib instances. This vulnerability is fixed in 0.36.0.
|
|||||
| CVE-2025-7105 | 2026-02-03 | N/A | 5.7 MEDIUM | ||
|
A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork` to fork numerous contents rapidly. If the forked content includes a Mermaid graph with a large number of nodes, it can lead to a JavaScript heap out of memory error upon service restart, causing a denial of service. This issue affects the latest version of the product.
|
|||||
| CVE-2025-6208 | 2026-02-03 | N/A | 5.3 MEDIUM | ||
|
The `SimpleDirectoryReader` component in `llama_index.core` version 0.12.23 suffers from uncontrolled memory consumption due to a resource management flaw. The vulnerability arises because the user-specified file limit (`num_files_limit`) is applied after all files in a directory are loaded into memory. This can lead to memory exhaustion and degraded performance, particularly in environments with limited resources. The issue is resolved in version 0.12.41.
|
|||||
| CVE-2026-0599 | 2026-02-03 | N/A | 7.5 HIGH | ||
|
A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a blocking HTTP GET request, reading the entire response body into memory and cloning it before decoding. This behavior can lead to resource exhaustion, including network bandwidth saturation, memory inflation, and CPU over ...
Show More |
|||||
| CVE-2025-69198 | 1 Pterodactyl | 1 Panel | 2026-02-02 | N/A | 6.5 MEDIUM |
|
Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resource limits are applied on a per-server basis, and validated during the request cycle. However, in versions prior to 1.12.0, it is possible for a malicious user to send a massive volume of requests at the same time that would create more resources than ...
Show More |
|||||
| CVE-2025-69199 | 1 Pterodactyl | 1 Wings | 2026-02-02 | N/A | 6.5 MEDIUM |
|
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large number of connections and then request data through these sockets, causing an excessive volume of data over the network and overloading the host system memory and cpu. Additionally, there is not a limit applied to the total size of messages being sent or receive ...
Show More |
|||||
| CVE-2026-21696 | 1 Pterodactyl | 1 Wings | 2026-02-02 | N/A | 6.5 MEDIUM |
|
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1.12.0, Wings does not consider SQLite max parameter limit when processing activity log entries allowing for low privileged user to trigger a condition that floods the panel with activity records. After Wings sends activity logs to the panel it deletes the processed activity entries from the wings SQLite database. However, it does not consider the ma ...
Show More |
|||||
| CVE-2025-9278 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible.
|
|||||
| CVE-2025-9279 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
|
|||||
| CVE-2025-9281 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots
|
|||||
| CVE-2025-9280 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.
|
|||||
| CVE-2025-9282 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
|
|||||
| CVE-2025-9283 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
|
|||||
| CVE-2025-9464 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive.
|
|||||
| CVE-2025-9465 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
|
|||||
| CVE-2025-9466 | 1 Rockwellautomation | 2 Armorstart Lt, Armorstart Lt Firmware | 2026-02-02 | N/A | 7.5 HIGH |
|
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.
|
|||||
| CVE-2025-66959 | 1 Ollama | 1 Ollama | 2026-02-02 | N/A | 7.5 HIGH |
|
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
|
|||||
| CVE-2025-66960 | 1 Ollama | 1 Ollama | 2026-02-02 | N/A | 7.5 HIGH |
|
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function readGGUFV1String reads a string length from untrusted GGUF metadata
|
|||||
| CVE-2026-0517 | 1 Absolute | 1 Secure Access | 2026-02-02 | N/A | 7.5 HIGH |
|
CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure
Access Server prior to 14.20. An attacker can send a specially crafted packet
to a server and cause the server to crash
|
|||||
| CVE-2026-22239 | 1 Blusparkglobal | 1 Bluvoyix | 2026-02-02 | N/A | 5.3 MEDIUM |
|
The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attacker to send unsolicited emails to anyone on behalf of the company.
|
|||||
| CVE-2025-59464 | 1 Nodejs | 1 Node.js | 2026-01-30 | N/A | 7.5 HIGH |
|
A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS connections. Over time this can lead to resource exhaustion and denial of service.
|
|||||
| CVE-2025-59465 | 1 Nodejs | 1 Node.js | 2026-01-30 | N/A | 7.5 HIGH |
|
A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets, for example:
```
server.on('secureConnection', socket => {
socket.on('error', err => {
console.log(err)
})
})
```
|
|||||
| CVE-2026-21637 | 1 Nodejs | 1 Node.js | 2026-01-30 | N/A | 7.5 HIGH |
|
A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client ca ...
Show More |
|||||
| CVE-2026-22258 | 1 Oisf | 1 Suricata | 2026-01-30 | N/A | 7.5 HIGH |
|
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB are also vulnerable. DCERPC/TCP in the default configuration should not be vulnerable as the default stream depth is limited to 1MiB. Versions 8.0.3 and 7.0.14 contain a patch. Some workarounds are avail ...
Show More |
|||||
| CVE-2026-22259 | 1 Oisf | 1 Suricata | 2026-01-30 | N/A | 7.5 HIGH |
|
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a workaround, disable the DNP3 parser in the suricata yaml (disabled by default).
|
|||||
| CVE-2026-21945 | 1 Oracle | 4 Graalvm, Graalvm For Jdk, Jdk and 1 more | 2026-01-30 | N/A | 7.5 HIGH |
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and 21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle ...
Show More |
|||||