VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

623 CVEsRSS

CVE-2026-82001Medium· 5.5
2w ago

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application deni…

▾ Sunlitadobe · acrobatEPSS 0.23%via NVD
CVE-2026-76000Medium· 6.5
2w ago

ColdFusion is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

ColdFusion is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-o…

▾ Sunlitadobe · coldfusionEPSS 0.41%via NVD
CVE-2026-28596Medium· 5.5
2w ago

In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion

In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interacti…

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-28617Medium· 5.5
2w ago

In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion

In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for ex…

▾ Sunlitgoogle · androidEPSS 0.09%via NVD
CVE-2026-83968High· 7.8
2w ago

Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-72923High· 7.5
2w ago

In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled …

In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled …

▾ TwilightMicrosoft · OpenApi.YamlReaderEPSS 1.2%via NVD
CVE-2026-86734Medium· 6.5
2w ago

Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering

Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can s…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.55%via NVD
CVE-2026-86135High· 7.0
2w ago

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a …

A Cross-Site Request Forgery (CSRF) vulnerability in WatchGuard Dimension's database snapshot creation feature allows a remote attacker to trigger unauthorized snapshot creation by tricking an authenticated administrator into visiting a …

▾ TwilightWatchGuard · DimensionEPSS 0.25%via NVD
CVE-2026-79378High· 7.5
2w ago

An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.

An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.

▾ TwilightEPSS 0.61%via NVD
CVE-2026-12611High· 8.7
2w ago

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

▾ TwilightEclipse Foundation · Eclipse JettyEPSS 0.25%via NVD
CVE-2026-86515Medium· 4.3PoC
2w ago

A security vulnerability has been detected in vgmstream up to r2117

A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource c…

▾ TwilightEPSS 0.59%via NVD
CVE-2026-86513Medium· 5.3PoC
2w ago

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the compon…

▾ Twilightjava-json-tools · jackson-coreutilsEPSS 0.70%via NVD
CVE-2026-86511Medium· 5.3PoC
2w ago

A vulnerability was found in java-json-tools jackson-coreutils 2.0

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation res…

▾ Twilightjava-json-tools · jackson-coreutilsEPSS 0.70%via NVD
CVE-2026-86420Low· 3.7
2w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

▾ Sunlitimagemagick · imagemagickEPSS 0.32%via NVD
CVE-2026-86452High· 7.5
2w ago

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled em…

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoint accepted an attacker-controlled em…

▾ Twilightmisp-project · mispEPSS 0.54%via NVD
CVE-2026-86319Medium· 5.3PoC
2w ago

A vulnerability has been found in java-json-tools json-patch up to 1.13

A vulnerability has been found in java-json-tools json-patch up to 1.13. Affected by this vulnerability is the function JsonPatch.apply of the file src/main/java/com/github/fge/jsonpatch/JsonPatch.java of the component Patch Operation Ha…

▾ Twilightjava-json-tools · json-patchEPSS 0.70%via NVD
CVE-2026-86421Low· 3.7
2w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.

▾ Sunlitimagemagick · imagemagickEPSS 0.45%via NVD
CVE-2026-86347Medium· 6.5
2w ago

Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *

Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended role restrictions applied to neighboring te…

▾ Sunlitmisp-project · mispEPSS 0.43%via NVD
CVE-2022-51018Medium· 6.5
2w ago

PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length

PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs'), causing excess bandwidth consumpti…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.42%via NVD
CVE-2026-86255Medium· 6.5
3w ago

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endp…

▾ Sunlitwger · wgerEPSS 0.44%via NVD
CVE-2026-86250High· 7.5
3w ago

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.49%via NVD
CVE-2020-37277Medium· 6.5
3w ago

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple confli…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.29%via NVD
CVE-2021-44320High· 7.5
3w ago

Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks

Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood atta…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-85585High· 7.5
3w ago

SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction

SiYuan before v3.8.2 contains an unbounded resource consumption vulnerability in the request-concurrency middleware that retains mutex entries for every unique request path without eviction. Unauthenticated attackers can send numerous un…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-85703Medium· 6.5PoC
3w ago

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc

A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulati…

▾ Twilightramon-victor · freegpt-webuiEPSS 0.55%via NVD
CVE-2021-44319High· 7.5
3w ago

Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service

Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during m…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-19645Medium· 6.5
3w ago

IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangin…

IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangin…

▾ SunlitIBM · MQ AgentEPSS 0.29%via NVD
CVE-2026-55512Medium· 5.3PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limi…

▾ Twilightforgekeep · nebula-meshEPSS 0.60%via NVD
CVE-2026-85443High· 7.5
3w ago

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake

MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker can open a TCP c…

▾ Twilightthemoos · core-moosEPSS 0.63%via NVD
CVE-2026-84886Medium· 5.3
3w ago

A vulnerability was determined in simular-ai Agent-S up to 0.3.2

A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulation of the argum…

▾ SunlitEPSS 0.64%via NVD
CWE-400 vulnerabilities (CVEs) — page 8 · VulnSea