VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

622 CVEsRSS

CVE-2026-54609High· 8.6
2mo ago

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding

▾ Twilightquietterminal · com.quietterminal:qti-neonEPSS 0.46%via GHSA
CVE-2025-63913High· 7.5
2mo ago

An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.

An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-17501Medium· 5.3
2mo ago

A flaw has been found in ggml-org llama.cpp e15efe0

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes allocation of …

▾ SunlitEPSS 0.72%via NVD
CVE-2026-55685Medium· 6.5
2mo ago

react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)

A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…

▾ SunlitRed Hat · Red Hat OpenShift AI 3.4EPSS 0.71%via CSAF
GHSA-68r5-9hpg-7qw9Critical· 9.4
2mo ago

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-dsml-servletvia GHSA
GHSA-g5vv-q72c-7j78High· 7.5
2mo ago

@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion

▾ Twilightanephenix · @anephenix/hubvia GHSA
GHSA-gm3r-q2wp-hw87High
2mo ago

Shescape: Quadratic-time denial of service in the flag-protection

Shescape: Quadratic-time denial of service in the flag-protection

▾ Twilightshescape · shescapevia GHSA
GHSA-hmj8-5xmh-5573High· 7.5
2mo ago

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

▾ Twilightlibp2p · libp2pvia GHSA
CVE-2026-44907High· 7.5
2mo ago

react-server-dom: Denial of Service in Server Functions

react-server-dom: Denial of Service in Server Functions

▾ Twilightreact-server-dom-webpack · react-server-dom-webpackEPSS 0.60%via GHSA
GHSA-v74w-7mr3-4qg3High· 7.5
2mo ago

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion

▾ Twilightnetty · io.netty:netty-codec-xmlvia GHSA
GHSA-r292-9mhp-454mMedium· 5.3
2mo ago

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

▾ Sunlittar · tarvia GHSA
CVE-2026-55594Medium· 5.3
2mo ago

ImageMagick: Stack Overflow in MVG decoder due to missing depth check.

ImageMagick: Stack Overflow in MVG decoder due to missing depth check.

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.40%via GHSA
CVE-2026-55595Medium· 4.7
2mo ago

ImageMagick: Infinite Loop in connected-components when providing invalid arguments

ImageMagick: Infinite Loop in connected-components when providing invalid arguments

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.12%via GHSA
GHSA-rvhp-75f6-9jqhLow· 3.3
2mo ago

ImageMagick: Policy Bypass possible with matrix-backed operations

ImageMagick: Policy Bypass possible with matrix-backed operations

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-qh5g-q395-cx4jLow· 3.7
2mo ago

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

ImageMagick: Heap-use-after-free via XMP profile could result in a crash

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-14257High· 7.5
2mo ago

brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)

A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-59936High
2mo ago

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

▾ Twilightpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-59932High· 7.5
2mo ago

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.70%via GHSA
CVE-2026-59933High· 7.5
2mo ago

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

▾ Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.70%via GHSA
CVE-2026-59937Medium
2mo ago

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

▾ Sunlitpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-59941MediumPoC
2mo ago

Dompdf: Uncontrolled resource consumption based on declared BMP dimensions

Dompdf: Uncontrolled resource consumption based on declared BMP dimensions

▾ Twilightdompdf · dompdf/dompdfEPSS 0.64%via GHSA
CVE-2026-59942Medium
2mo ago

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.90%via GHSA
CVE-2024-7708High· 7.5
2mo ago

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

▾ Twilighteclipse · org.eclipse.jetty:jetty-serverEPSS 0.44%via GHSA
CVE-2026-63136Medium· 6.5
2mo ago

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhau…

▾ Sunlitelastic · elasticsearchEPSS 0.42%via NVD
CVE-2026-56145Medium· 6.5
2mo ago

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they co…

▾ Sunlitelastic · elasticsearchEPSS 0.47%via NVD
CVE-2026-60647High· 7.1
2mo ago

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management)

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low priv…

▾ Twilightoracle · webcenter_contentEPSS 0.38%via NVD
CVE-2026-60411Medium· 6.5
2mo ago

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver)

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: ttcserver). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows unauthenticated attack…

▾ Sunlitoracle · timesten_in-memory_databaseEPSS 0.37%via NVD
CVE-2026-60410Medium· 4.3
2mo ago

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileg…

▾ Sunlitoracle · timesten_in-memory_databaseEPSS 0.37%via NVD
CVE-2026-60404Medium· 6.5
2mo ago

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileg…

▾ Sunlitoracle · timesten_in-memory_databaseEPSS 0.42%via NVD
CVE-2026-60403Medium· 6.5
2mo ago

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileg…

▾ Sunlitoracle · timesten_in-memory_databaseEPSS 0.42%via NVD
CWE-400 vulnerabilities (CVEs) — page 13 · VulnSea