Total
3694 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-70999 | 1 Oneflow | 1 Oneflow | 2026-07-05 | N/A | 7.5 HIGH |
| A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted device ID. | |||||
| CVE-2025-67445 | 1 Totolink | 2 X5000r, X5000r Firmware | 2026-07-05 | N/A | 7.5 HIGH |
| TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the CONTENT_LENGTH environment variable and allocates memory using malloc (CONTENT_LENGTH + 1) without sufficient bounds checking. When lighttpd s request size limit is not enforced, a crafted large POST request can cause memory exhaustion or a segmentation fault, leading to a crash of the management CGI and loss of availability of the web interface. | |||||
| CVE-2025-65891 | 1 Oneflow | 1 Oneflow | 2026-07-05 | N/A | 7.5 HIGH |
| A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow.cuda.get_device_properties() with an invalid or negative device index. | |||||
| CVE-2025-65890 | 1 Oneflow | 1 Oneflow | 2026-07-05 | N/A | 7.5 HIGH |
| A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.synchronize() with an invalid or out-of-range GPU device index. | |||||
| CVE-2025-65889 | 1 Oneflow | 1 Oneflow | 2026-07-05 | N/A | 7.5 HIGH |
| A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2025-65888 | 1 Oneflow | 1 Oneflow | 2026-07-05 | N/A | 7.5 HIGH |
| A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service (DoS) via a negative or excessively large dimension value. | |||||
| CVE-2025-65886 | 1 Oneflow | 1 Oneflow | 2026-07-05 | N/A | 7.5 HIGH |
| A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying crafted tensor shapes. | |||||
| CVE-2025-63560 | 1 Kiloview | 2 E3, E3 Firmware | 2026-07-05 | N/A | 7.5 HIGH |
| An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to cause a denial of service via the systemctrl API System/reFactory component. | |||||
| CVE-2025-61301 | 2026-07-05 | N/A | 7.5 HIGH | ||
| Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submit samples to cause incomplete or missing behavioral analysis reports by generating deeply nested or oversized behavior data that trigger MongoDB BSON limits or orjson recursion errors when the sample executes in the sandbox. | |||||
| CVE-2025-60349 | 2026-07-05 | N/A | 7.5 HIGH | ||
| An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver. Any processes listed under registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxscan\Files will be terminated. | |||||
| CVE-2025-56572 | 1 Ebradyjobory | 1 Finance.js | 2026-07-05 | N/A | 7.5 HIGH |
| An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter. | |||||
| CVE-2025-51741 | 1 Interviewx | 1 Echo | 2026-07-05 | N/A | 7.5 HIGH |
| An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to cause the server to send email verification messages to arbitrary users via the /sendEmailCodeForResetPwd endpoint potentially causing a denial of service to the server or the downstream users. | |||||
| CVE-2025-46171 | 1 Vbulletin | 1 Vbulletin | 2026-07-05 | N/A | 5.4 MEDIUM |
| vBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a sufficiently large buddy list, processing the list can consume excessive memory, exhausting system resources and crashing the forum. | |||||
| CVE-2025-44653 | 1 H3c | 2 Gr2200, Gr2200 Firmware | 2026-07-05 | N/A | 7.5 HIGH |
| In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are connected. | |||||
| CVE-2025-44651 | 1 Trendnet | 2 Tpl-430ap, Tpl-430ap Firmware | 2026-07-05 | N/A | 7.5 HIGH |
| In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are connected. | |||||
| CVE-2024-42849 | 1 Silverpeas | 1 Silverpeas | 2026-07-05 | N/A | 6.5 MEDIUM |
| An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function. | |||||
| CVE-2026-9002 | 1 Ibm | 1 Websphere Extreme Scale | 2026-07-02 | N/A | 6.5 MEDIUM |
| IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The application processes deeply nested Protocol Buffers messages and attacker-controlled length prefixes without sufficient bounds checking, which may allow an attacker on the same network to trigger a StackOverflowError or OutOfMemoryError, resulting in a crash of the WebSphere Application Server JVM. | |||||
| CVE-2026-47262 | 1 Linuxfoundation | 1 Containerd | 2026-07-02 | N/A | 5.5 MEDIUM |
| containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2. | |||||
| CVE-2026-55594 | 1 Imagemagick | 1 Imagemagick | 2026-07-02 | N/A | 5.3 MEDIUM |
| ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. | |||||
| CVE-2026-55595 | 1 Imagemagick | 1 Imagemagick | 2026-07-02 | N/A | 4.7 MEDIUM |
| ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the connected-components option an infinite loop will occur. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26. | |||||
