Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Hotel Booking System HIGH 7.5
CVE-2023-51301

A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive am…

No fix yet
Fix from $1,950 2025-02-19
Event Booking Calendar HIGH 7.5
CVE-2023-51293

A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an exce…

No fix yet
Fix from $1,950 2025-02-19
Unclassified MEDIUM 6.8
CVE-2024-57782

An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.

No fix yet
Fix from $1,600 2025-02-13
Headunit Ntg6 Mercedes Benz User Experience HIGH 7.5
CVE-2023-34397

Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will …

Fix: after 2021
Fix from $1,950 2025-02-13
Unclassified MEDIUM 6.2
CVE-2025-0426

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTT…

Mitigation only
Fix from $1,600 2025-02-13
Learndash HIGH 7.5
CVE-2024-56940

An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads.

Mitigation only
Fix from $1,950 2025-02-12
Exynos 2200 Firmware HIGH 7.5
CVE-2024-46923

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service at amdgpu_c…

Mitigation only
Fix from $1,950 2025-02-12
Audiobookshelf HIGH 8.2
CVE-2025-25205

Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication by…

Fix: 2.19.1+
Fix from $1,950 2025-02-12
Windows 10 1607 HIGH 7.5
CVE-2025-21351

Windows Active Directory Domain Services API Denial of Service Vulnerability

Fix: 10.0.14393.7785 / 10.0.17763.6893+
Fix from $1,950 2025-02-11
Windows 10 1507 MEDIUM 6.5
CVE-2025-21352

Internet Connection Sharing (ICS) Denial of Service Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,600 2025-02-11
Windows 10 1507 HIGH 7.5
CVE-2025-21181

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Unclassified MEDIUM 5.3
CVE-2024-23814

The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving speciall…

Mitigation only
Fix from $1,600 2025-02-11
Netty MEDIUM 5.5
CVE-2025-25193

Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe read…

Fix: 4.1.118+
Fix from $1,600 2025-02-10
Safari MEDIUM 6.5
CVE-2024-54658

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, vi…

Fix: 1.1 / 10.4+
Fix from $1,600 2025-02-10
Unclassified MEDIUM 6.5
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4…

Patch available
Fix from $1,600 2025-02-10
Floodlight MEDIUM 5.5
CVE-2024-57672

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing mo…

Mitigation only
Fix from $1,600 2025-02-06
Floodlight MEDIUM 5.5
CVE-2024-57673

An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module

No fix yet
Fix from $1,600 2025-02-06
James Server HIGH 7.5
CVE-2024-45626

Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can resu…

Fix: 3.7.6 / 3.8.2+
Fix from $1,950 2025-02-06
Unclassified HIGH 7.5
CVE-2024-57079

A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a craft…

Mitigation only
Fix from $1,950 2025-02-05
Unclassified HIGH 7.5
CVE-2024-57081

A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a …

Mitigation only
Fix from $1,950 2025-02-05
Unclassified MEDIUM 6.5
CVE-2024-57082

A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying …

Mitigation only
Fix from $1,600 2025-02-05
Unclassified HIGH 7.5
CVE-2024-57085

A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a c…

Mitigation only
Fix from $1,950 2025-02-05
Unclassified HIGH 7.5
CVE-2024-57074

A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted paylo…

Mitigation only
Fix from $1,950 2025-02-05
Unclassified HIGH 7.5
CVE-2024-57075

A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted pa…

Mitigation only
Fix from $1,950 2025-02-05
Unclassified HIGH 7.5
CVE-2024-57076

A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS) via supplying a crafted pay…

Mitigation only
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-21087

When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an incr…

Fix: 16.1.6 / 17.1.2+
Fix from $1,950 2025-02-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2025-20058

When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. No…

Fix: 16.1.6 / 17.1.2+
Fix from $1,950 2025-02-05
Discourse MEDIUM 6.5
CVE-2024-53851

Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enfor…

Fix: 3.3.3 / 3.4.0+
Fix from $1,600 2025-02-04
Open5gs HIGH 7.5
CVE-2024-56921

An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handli…

Patch available
Fix from $1,950 2025-02-03
Open5gs HIGH 7.5
CVE-2024-57519

An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.

Patch available
Fix from $1,950 2025-01-28