Total
1580 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2020-37067 | 2026-02-04 | N/A | 9.8 CRITICAL | ||
|
Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service.
|
|||||
| CVE-2026-24514 | 2026-02-04 | N/A | 6.5 MEDIUM | ||
|
A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.
|
|||||
| CVE-2020-37039 | 2026-02-03 | N/A | 7.5 HIGH | ||
|
Frigate 2.02 contains a denial of service vulnerability that allows attackers to crash the application by sending oversized input to the command line interface. Attackers can generate a payload of 8000 repeated characters and paste it into the application's command line field to trigger an application crash.
|
|||||
| CVE-2020-37038 | 2026-02-03 | N/A | 7.5 HIGH | ||
|
Code Blocks 20.03 contains a denial of service vulnerability that allows attackers to crash the application by manipulating input in the FSymbols search field. Attackers can paste a large payload of 5000 repeated characters into the search field to trigger an application crash.
|
|||||
| CVE-2025-66560 | 1 Quarkus | 1 Quarkus | 2026-02-03 | N/A | 5.9 MEDIUM |
|
Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerability exists in the HTTP layer of Quarkus REST related to response handling. When a response is being written, the framework waits for previously written response chunks to be fully transmitted before proceeding. If the client connection is dropped during this waiting period, the associated worker thread is never released and becomes permanently bloc ...
Show More |
|||||
| CVE-2025-69199 | 1 Pterodactyl | 1 Wings | 2026-02-02 | N/A | 6.5 MEDIUM |
|
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large number of connections and then request data through these sockets, causing an excessive volume of data over the network and overloading the host system memory and cpu. Additionally, there is not a limit applied to the total size of messages being sent or receive ...
Show More |
|||||
| CVE-2026-21696 | 1 Pterodactyl | 1 Wings | 2026-02-02 | N/A | 6.5 MEDIUM |
|
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1.12.0, Wings does not consider SQLite max parameter limit when processing activity log entries allowing for low privileged user to trigger a condition that floods the panel with activity records. After Wings sends activity logs to the panel it deletes the processed activity entries from the wings SQLite database. However, it does not consider the ma ...
Show More |
|||||
| CVE-2026-23962 | 1 Joinmastodon | 1 Mastodon | 2026-02-02 | N/A | 7.5 HIGH |
|
Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit on the maximum number of poll options for remote posts, allowing attackers to create polls with a very large amount of options, greatly increasing resource consumption. Depending on the number of poll options, an attacker can cause disproportionate resource usage in both Mastodon servers and clients, potentially causing Denial of Service either ser ...
Show More |
|||||
| CVE-2026-23963 | 1 Joinmastodon | 1 Mastodon | 2026-02-02 | N/A | 4.3 MEDIUM |
|
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a maximum length for the names of lists or filters, or for filter keywords, allowing any user to set an arbitrarily long string as the name or keyword. Any local user can abuse the list or filter fields to cause disproportionate storage and computing resource usage. They can additionally cause their own web interface to be unusable, although they mu ...
Show More |
|||||
| CVE-2026-23881 | 1 Kyverno | 1 Kyverno | 2026-02-02 | N/A | 7.7 HIGH |
|
Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of service by crafting policies that exponentially amplify string data through context variables. Versions 1.16.3 and 1.15.3 contain a patch for the vulnerability.
|
|||||
| CVE-2026-23490 | 2026-02-01 | N/A | 7.5 HIGH | ||
|
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.
|
|||||
| CVE-2025-68934 | 1 Discourse | 1 Discourse | 2026-01-30 | N/A | 6.5 MEDIUM |
|
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, authenticated users can submit crafted payloads to /drafts.json that cause O(n^2) processing in Base62.decode, tying up workers for 35-60 seconds per request. This affects all users as the shared worker pool becomes exhausted. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. Lowering the max_draft_length site setting reduces attack surface but does not full ...
Show More |
|||||
| CVE-2025-68659 | 1 Discourse | 1 Discourse | 2026-01-30 | N/A | 4.3 MEDIUM |
|
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application level denial of service vulnerabilityin the username change functionality at try.discourse.org. The vulnerability allows attackers to cause noticeable server delays and resource exhaustion by sending large JSON payloads to the username preference endpoint PUT /u//preferences/username, resulting in degraded performance for other users and endpoints. This issue is patche ...
Show More |
|||||
| CVE-2024-34703 | 2026-01-30 | N/A | 7.5 HIGH | ||
|
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior to versions 3.3.0 and 2.19.4, an attacker could present an ECDSA X.509 certificate using explicit encoding where the parameters are very large. The proof of concept used a 16Kbit prime for this purpose. When parsing, the parameter is checked to be prime, causing excessive computation. This was patched in 2.19.4 and 3.3.0 to all ...
Show More |
|||||
| CVE-2026-22258 | 1 Oisf | 1 Suricata | 2026-01-30 | N/A | 7.5 HIGH |
|
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, crafted DCERPC traffic can cause Suricata to expand a buffer w/o limits, leading to memory exhaustion and the process getting killed. While reported for DCERPC over UDP, it is believed that DCERPC over TCP and SMB are also vulnerable. DCERPC/TCP in the default configuration should not be vulnerable as the default stream depth is limited to 1MiB. Versions 8.0.3 and 7.0.14 contain a patch. Some workarounds are avail ...
Show More |
|||||
| CVE-2026-22259 | 1 Oisf | 1 Suricata | 2026-01-30 | N/A | 7.5 HIGH |
|
Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, specially crafted traffic can cause Suricata to consume large amounts of memory while parsing DNP3 traffic. This can lead to the process slowing down and running out of memory, potentially leading to it getting killed by the OOM killer. Versions 8.0.3 or 7.0.14 contain a patch. As a workaround, disable the DNP3 parser in the suricata yaml (disabled by default).
|
|||||
| CVE-2025-13751 | 2 Microsoft, Openvpn | 2 Windows, Openvpn | 2026-01-30 | N/A | 5.5 MEDIUM |
|
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.
|
|||||
| CVE-2021-47791 | 1 Smartftp | 1 Smartftp | 2026-01-30 | N/A | 7.5 HIGH |
|
SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can trigger crashes by entering malformed paths, using invalid IP addresses, or clearing connection history in the client's interface.
|
|||||
| CVE-2021-47793 | 1 Telegram | 1 Telegram Desktop | 2026-01-30 | N/A | 7.5 HIGH |
|
Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payload. Attackers can generate a 9 million byte buffer and paste it into the messaging interface to trigger an application crash.
|
|||||
| CVE-2025-27795 | 1 Graphicsmagick | 1 Graphicsmagick | 2026-01-29 | N/A | 4.3 MEDIUM |
|
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
|
|||||
| CVE-2020-36943 | 2026-01-29 | N/A | 7.5 HIGH | ||
|
aSc TimeTables 2021.6.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting subject title fields with excessive data. Attackers can generate a 10,000-character buffer and paste it into the subject title to trigger application instability and potential crash.
|
|||||
| CVE-2025-55102 | 2026-01-29 | N/A | N/A | ||
|
A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet Too Big" with more than 15 different source address can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.
|
|||||
| CVE-2020-36950 | 2026-01-29 | N/A | 6.5 MEDIUM | ||
|
Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.
|
|||||
| CVE-2020-36946 | 2026-01-29 | N/A | 7.5 HIGH | ||
|
SyncBreeze 10.0.28 contains a denial of service vulnerability in the login endpoint that allows remote attackers to crash the service. Attackers can send an oversized payload in the login request to overwhelm the application and potentially disrupt service availability.
|
|||||
| CVE-2025-61723 | 1 Golang | 1 Go | 2026-01-29 | N/A | 7.5 HIGH |
|
The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
|
|||||
| CVE-2025-61724 | 1 Golang | 1 Go | 2026-01-29 | N/A | 5.3 MEDIUM |
|
The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
|
|||||
| CVE-2025-59089 | 2026-01-28 | N/A | 5.9 MEDIUM | ||
|
If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact that kdcproxy does not enforce bounds on TCP response length to conduct a denial-of-service attack. While receiving the KDC's response, kdcproxy copies the entire buffered stream into a new
buffer on each recv() call, even when the transfer is incomplete, causing excessive memory allocation and CPU usage. Additionally, kdcproxy accepts incoming resp ...
Show More |
|||||
| CVE-2026-22773 | 1 Vllm | 1 Vllm | 2026-01-27 | N/A | 6.5 MEDIUM |
|
vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a specially crafted 1x1 pixel image. This causes a tensor dimension mismatch that results in an unhandled runtime error, leading to complete server termination. This issue has been patched in version 0.12.0.
|
|||||
| CVE-2025-58578 | 1 Sick | 1 Enterprise Analytics | 2026-01-27 | N/A | 3.8 LOW |
|
A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.
|
|||||
| CVE-2025-58582 | 1 Sick | 1 Enterprise Analytics | 2026-01-27 | N/A | 5.3 MEDIUM |
|
If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.
|
|||||
| CVE-2025-14525 | 2026-01-27 | N/A | 6.4 MEDIUM | ||
|
A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability to store VM configuration updates, effectively blocking changes to the Virtual Machine Instance (VMI). This allows the VM user to restrict the VM administrator's ability to manage the VM, leading to a denial of service for administrative operations.
|
|||||
| CVE-2026-1224 | 2026-01-27 | N/A | 4.9 MEDIUM | ||
|
Tanium addressed an uncontrolled resource consumption vulnerability in Discover.
|
|||||
| CVE-2026-1102 | 1 Gitlab | 1 Gitlab | 2026-01-26 | N/A | 5.3 MEDIUM |
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending repeated malformed SSH authentication requests.
|
|||||
| CVE-2025-13927 | 1 Gitlab | 1 Gitlab | 2026-01-26 | N/A | 7.5 HIGH |
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.
|
|||||
| CVE-2024-47502 | 1 Juniper | 1 Junos Os Evolved | 2026-01-26 | N/A | 7.5 HIGH |
|
An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS).
In specific cases the state of TCP sessions that are terminated is not cleared, which over time leads to an exhaustion of resources, preventing new connections to the control plane from being established.
A continuously increasing number of connections shown by:
user@host > show system c ...
Show More |
|||||
| CVE-2021-47771 | 1 Cinspiration | 1 Rdp Manager | 2026-01-26 | N/A | 5.5 MEDIUM |
|
RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to crash the application. Attackers can add oversized entries in Verbindungsname and Server fields to permanently freeze and crash the software, potentially requiring full reinstallation.
|
|||||
| CVE-2025-11044 | 2026-01-26 | N/A | 6.8 MEDIUM | ||
|
An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on affected devices.
|
|||||
| CVE-2021-47865 | 2026-01-26 | N/A | 7.5 HIGH | ||
|
ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server connection limits and block legitimate user access.
|
|||||
| CVE-2021-47875 | 2026-01-26 | N/A | 9.8 CRITICAL | ||
|
GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a payload with 8000 repeated characters and paste it into the calculator's input field to trigger an application crash.
|
|||||
| CVE-2021-47877 | 2026-01-26 | N/A | 7.5 HIGH | ||
|
GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer. Attackers can generate a payload of 8000 repeated characters to overwhelm the input field and cause the application to become unresponsive.
|
|||||