Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Nextcloud Server MEDIUM 6.5
CVE-2024-52520

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downlo…

Fix: 27.1.11.8 / 28.0.10+
Fix from $1,600 2024-11-15
Unclassified HIGH 8.6
CVE-2023-20125

A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacker to exhaust system resources…

Mitigation only
Fix from $1,950 2024-11-15
Unclassified HIGH 7.5
CVE-2024-48989

A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of servic…

Mitigation only
Fix from $1,950 2024-11-13
Powerlogic Pm5341 Firmware HIGH 7.5
CVE-2024-9409

CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss…

Fix: 2.4.0 / 2.7.0+
Fix from $1,950 2024-11-13
Netty MEDIUM 5.5
CVE-2024-47535

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients…

Fix: 4.1.115+
Fix from $1,600 2024-11-12
Sinec Ins HIGH 7.5
CVE-2024-46891

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of …

Fix: after 1.0
Fix from $1,950 2024-11-12
Unclassified HIGH 8.7
CVE-2024-10314

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported …

Mitigation only
Fix from $1,950 2024-11-11
Unclassified HIGH 8.7
CVE-2024-10344

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol …

Mitigation only
Fix from $1,950 2024-11-11
Unclassified HIGH 8.7
CVE-2024-10345

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karo…

Mitigation only
Fix from $1,950 2024-11-11
Unclassified MEDIUM 5.3
CVE-2024-38826

Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be used to run a denial of service …

Mitigation only
Fix from $1,600 2024-11-11
Harmonyos MEDIUM 5.5
CVE-2024-51513

Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consu…

No fix yet
Fix from $1,600 2024-11-05
Office Anywhere HIGH 7.5
CVE-2024-10599

A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the …

Fix: after 11.7
Fix from $1,950 2024-10-31
Gnark MEDIUM 5.5
CVE-2024-50354

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verificatio…

Fix: 0.12.0+
Fix from $1,600 2024-10-31
Wbr 6012 Firmware HIGH 7.5
CVE-2024-31152EPSS 18%

The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafte…

No fix yet
Fix from $1,950 2024-10-30
Firefox HIGH 7.5
CVE-2024-10466

By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vul…

Fix: 128.4.0 / 132.0+
Fix from $1,950 2024-10-29
Quart HIGH 7.5
CVE-2024-49767

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a versi…

Fix: 0.19.7 / 3.0.6+
Fix from $1,950 2024-10-25
Adaptive Security Appliance Software MEDIUM 5.3
CVE-2024-20526

A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a deni…

Mitigation only
Fix from $1,600 2024-10-23
Secure Firewall Threat Defense HIGH 7.5
CVE-2024-20351

A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco Fire…

Mitigation only
Fix from $1,950 2024-10-23
Http Proxy Middleware HIGH 7.5
CVE-2024-21536

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an Unhandled…

Fix: 2.0.7 / 3.0.3+
Fix from $1,950 2024-10-19
MySQL MEDIUM 6.5
CVE-2024-21230

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior,…

Fix: after 8.4.2
Fix from $1,600 2024-10-15
MySQL MEDIUM 6.5
CVE-2024-21196

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 and prior, …

Fix: after 8.4.2
Fix from $1,600 2024-10-15
Splunk MEDIUM 6.5
CVE-2024-45736

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a …

Fix: 9.1.6 / 9.1.2312.111+
Fix from $1,600 2024-10-14
Jetty MEDIUM 6.5
CVE-2024-8184

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-o…

Fix: 9.4.56 / 10.0.24+
Fix from $1,600 2024-10-14
Jetty MEDIUM 6.5
CVE-2024-6762

Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.

Fix: 10.0.18 / 11.0.18+
Fix from $1,600 2024-10-14
Active Iq Unified Manager HIGH 7.5
CVE-2024-9823

There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attac…

Fix: 9.4.54 / 10.0.18+
Fix from $1,950 2024-10-14
Junos HIGH 7.5
CVE-2024-47497

An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and E…

Fix: 21.4+
Fix from $1,950 2024-10-11
Telerik Reporting MEDIUM 6.5
CVE-2024-7294

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limit…

Fix: 10.2.24.806+
Fix from $1,600 2024-10-09
Windows Server 2016 HIGH 7.5
CVE-2024-43575

Windows Hyper-V Denial of Service Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $1,950 2024-10-08
Windows Server 2008 HIGH 7.5
CVE-2024-43544

Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $1,950 2024-10-08
Windows Server 2008 HIGH 7.5
CVE-2024-43545

Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $1,950 2024-10-08