Skip to main content

CWE archive

CWE-400 CVEs

Programmatic archive

3,267 CVEs tagged with CWE-40059 Critical, 1,606 High, 1,466 Medium, 134 Low, 2 Unrated.

CVE-2026-54428

Published Jul 1, 2026

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-49090

Published Jul 1, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially cra…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-54399

Published Jul 1, 2026

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker t…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-2891

Published Jul 1, 2026

The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data. HP is releasing updates to mi…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57962

Published Jul 1, 2026

A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thun…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-52197

Published Jun 30, 2026

An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57204

Published Jun 30, 2026

pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which le…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-9002

Published Jun 30, 2026

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application pr…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57081

Published Jun 30, 2026

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57080

Published Jun 30, 2026

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-50750

Published Jun 30, 2026

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attack…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13149

Published Jun 30, 2026

brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace…

CVSS 7.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-45822

Published Jun 30, 2026

decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-…

CVSS 6.6 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-56018

Published Jun 29, 2026

JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) the cleanup frees only the Nod…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-36478

Published Jun 26, 2026

An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/Dns…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47214

Published Jun 26, 2026

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-30041

Published Jun 26, 2026

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57914

Published Jun 26, 2026

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-48619

Published Jun 26, 2026

A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affec…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-38640

Published Jun 25, 2026

A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-38637

Published Jun 25, 2026

An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-54092

Published Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maxim…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-42005

Published Jun 25, 2026

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by def…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-52814

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an unauthenticated, asymmetric Denial of Service (DoS) attack. Th…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-33235

Published Jun 24, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template bloc…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Showing 101-125 of 3,267 CVEsPage 5 of 131