Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Aardvark Dns HIGH 7.5
CVE-2024-8418

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can …

Patch available
Fix from $1,950 2024-09-04
Flowise HIGH 7.5
CVE-2024-8182EPSS 14%

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulner…

Mitigation only
Fix from $1,950 2024-08-27
Unclassified MEDIUM 6.5
CVE-2024-43806

Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it's possible for the iterator t…

Mitigation only
Fix from $1,600 2024-08-26
GitLab MEDIUM 6.5
CVE-2024-8041

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 1…

Fix: 17.1.6 / 17.2.4+
Fix from $1,600 2024-08-22
Idol2 CRITICAL 9.8
CVE-2024-45166

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper r…

Fix: after 2.12
Fix from $2,300 2024-08-22
Unclassified CRITICAL 9.1
CVE-2024-45163

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain …

Mitigation only
Fix from $2,300 2024-08-22
Python HIGH 7.5
CVE-2024-7592

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contain…

Fix: 3.8.20 / 3.9.20+
Fix from $1,950 2024-08-19
Fugit HIGH 7.5
CVE-2024-43380

fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accept…

Fix: 1.11.1+
Fix from $1,950 2024-08-19
Silverpeas MEDIUM 6.5
CVE-2024-42849

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

Fix: after 6.4.2
Fix from $1,600 2024-08-16
Fh1206 Firmware HIGH 7.5
CVE-2024-42980

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function. This vulnerability allows at…

No fix yet
Fix from $1,950 2024-08-15
Fh1206 Firmware HIGH 7.5
CVE-2024-42981

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting function. This vulnerability …

No fix yet
Fix from $1,950 2024-08-15
Fh1206 Firmware HIGH 7.5
CVE-2024-42969

Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter function. This vulnerability all…

No fix yet
Fix from $1,950 2024-08-15
Fh1201 Firmware HIGH 7.5
CVE-2024-42950

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the Go parameter in the fromSafeClientFilter function. This vulnerability…

No fix yet
Fix from $1,950 2024-08-15
Fh1201 Firmware HIGH 7.5
CVE-2024-42951

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the mit_pptpusrpw parameter in the fromWizardHandle function. This vulner…

No fix yet
Fix from $1,950 2024-08-15
Fh1201 Firmware HIGH 7.5
CVE-2024-42943

Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWan function. This vulnerabi…

No fix yet
Fix from $1,950 2024-08-15
Big Ip Access Policy Manager HIGH 7.5
CVE-2024-41727

In BIG-IP tenants running on r2000 and r4000 series hardware, or BIG-IP Virtual Edition (VEs) using Intel E810 SR-IOV NIC, undisclosed traffic can ca…

Fix: 16.1.5+
Fix from $1,950 2024-08-14
Unclassified MEDIUM 6.9
CVE-2024-7567

A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the C…

Mitigation only
Fix from $1,600 2024-08-13
.net HIGH 7.5
CVE-2024-38168

.NET and Visual Studio Denial of Service Vulnerability

Fix: 8.0.8 / 17.6.18+
Fix from $1,950 2024-08-13
Uprof HIGH 7.8
CVE-2023-31348

A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Fix: 4.1.424 / 4.2.816+
Fix from $1,950 2024-08-13
Skyportd HIGH 7.5
CVE-2024-42481

Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skyport's lack of rate limiting on…

Fix: 0.2.2+
Fix from $1,950 2024-08-12
Cv Cuda MEDIUM 6.1
CVE-2024-0115

NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource co…

Mitigation only
Fix from $1,600 2024-08-12
GitLab MEDIUM 6.5
CVE-2024-5423

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting fr…

Fix: 17.0.6 / 17.1.4+
Fix from $1,600 2024-08-08
GitLab MEDIUM 6.5
CVE-2024-7610

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4…

Fix: 17.0.6 / 17.1.4+
Fix from $1,600 2024-08-08
GitLab MEDIUM 6.5
CVE-2024-4210

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4…

Fix: 17.0.6 / 17.1.4+
Fix from $1,600 2024-08-08
Django HIGH 7.5
CVE-2024-41989

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumptio…

Fix: 4.2.15 / 5.0.8+
Fix from $1,950 2024-08-07
Arubaos MEDIUM 5.3
CVE-2024-42398

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation …

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $1,600 2024-08-06
Arubaos MEDIUM 5.3
CVE-2024-42399

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation …

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $1,600 2024-08-06
Instantos MEDIUM 5.3
CVE-2024-42397

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Succes…

Fix: 8.10.0.13 / 8.12.0.2+
Fix from $1,600 2024-08-06
Privx CRITICAL 9.1
CVE-2024-30170

PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, and i…

Fix: 31.3 / 32.3+
Fix from $2,300 2024-08-06
Openshift Container Platform HIGH 7.7
CVE-2024-3056

A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with…

Fix: after 5.2.0
Fix from $1,950 2024-08-02