Export limit exceeded: 378335 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (378335 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-28101 | 1 Apollographql | 1 Apollo Router | 2026-01-02 | 7.5 High |
| The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router evaluate the `limits.http_max_request_bytes` configuration option after the entirety of the compressed payload is decompressed. If affected versions of the Router receive highly compressed payloads, this could result in significant memory consumption while the compressed payload is expanded. Router version 1.40.2 has a fix for the vulnerability. Those who are unable to upgrade may be able to implement mitigations at proxies or load balancers positioned in front of their Router fleet (e.g. Nginx, HAProxy, or cloud-native WAF services) by creating limits on HTTP body upload size. | ||||
| CVE-2024-29883 | 1 Miraheze | 1 Createwiki | 2026-01-02 | 4.9 Medium |
| CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work as intended, and always restricts visibility to those with the `(createwiki)` user right regardless of the settings one sets on a given wiki request. This may expose information to users who are not supposed to be able to access it. | ||||
| CVE-2023-50257 | 1 Eprosima | 1 Fast Dds | 2026-01-02 | 9.7 Critical |
| eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly disconnect a Subscriber and can deny a Subscriber attempting to connect. Afterwards, if the attacker sends the packet for disconnecting, which is data (`p[UD]`), to the Global Data Space (`239.255.0.1:7400`) using the said Publisher ID, all the Subscribers (Listeners) connected to the Publisher (Talker) will not receive any data and their connection will be disconnected. Moreover, if this disconnection packet is sent continuously, the Subscribers (Listeners) trying to connect will not be able to do so. Since the initial commit of the `SecurityManager.cpp` code (`init`, `on_process_handshake`) on Nov 8, 2016, the Disconnect Vulnerability in RTPS Packets Used by SROS2 has been present prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7. | ||||
| CVE-2023-36337 | 1 Inventory Management System Project | 1 Inventory Management System | 2026-01-02 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||||
| CVE-2025-22203 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22202 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22201 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22200 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22199 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22198 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22197 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22196 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22195 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22194 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22193 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22192 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22191 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22190 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22189 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||
| CVE-2025-22188 | 2026-01-01 | N/A | ||
| To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | ||||