Skip to main content

CWE archive

CWE-1050 CVEs

Programmatic archive

14 CVEs tagged with CWE-10500 Critical, 8 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2026-48779

Published Jun 17, 2026

ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.…

CVSS 7.5 · High
evidence mentions
26
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-44390

Published May 20, 2026

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Maliciou…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2026-41292

Published May 20, 2026

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending…

CVSS 6.6 · Medium
evidence mentions
6
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2026-4634

Published Apr 2, 2026

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to th…

CVSS 7.5 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-22263

Published Jan 27, 2026

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, inefficiency in http1 headers parsing can lead to slowdown over multiple packe…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-22261

Published Jan 27, 2026

Suricata is a network IDS, IPS and NSM engine. Prior to versions 8.0.3 and 7.0.14, various inefficiencies in xff handling, especially for alerts not triggered in a tx, can lead to…

CVSS 3.7 · Low
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-67419

Published Jan 5, 2026

A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48866

Published Jun 2, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47947

Published May 21, 2025

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32907

Published Apr 14, 2025

A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same rang…

CVSS 5.3 · Medium

CVE-2024-4068

Published May 14, 2024

The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1390

Published Mar 16, 2023

A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKB…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41039

Published Dec 1, 2021

In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11254

Published Apr 1, 2020

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1