Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unclassified MEDIUM 5.5
CVE-2023-31889

An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of …

Mitigation only
Fix from $1,600 2024-04-29
Unclassified HIGH 7.5
CVE-2024-32269

An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.

No fix yet
Fix from $1,950 2024-04-29
PHP HIGH 7.5
CVE-2024-2757

In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of non-space characters followed …

Fix: 8.3.5+
Fix from $1,950 2024-04-29
Jerryscript MEDIUM 5.5
CVE-2024-33259

Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-core/parser/js/js-scanner-util.…

No fix yet
Fix from $1,600 2024-04-26
Mattermost Server MEDIUM 6.5
CVE-2024-4183

Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, whic…

Fix: 8.1.12 / 9.4.5+
Fix from $1,600 2024-04-26
Mattermost Server MEDIUM 6.5
CVE-2024-22091

Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user i…

Fix: 8.1.12 / 9.5.3+
Fix from $1,600 2024-04-26
Python Jose MEDIUM 5.3
CVE-2024-33664

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE…

Fix: after 3.3.0
Fix from $1,600 2024-04-26
Unclassified HIGH 7.5
CVE-2023-6596

An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

Mitigation only
Fix from $1,950 2024-04-25
Mealie MEDIUM 6.5
CVE-2024-31994

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. Mealie…

Fix: 1.4.0+
Fix from $1,600 2024-04-19
Mealie MEDIUM 6.5
CVE-2024-31992

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a requ…

Fix: 1.4.0+
Fix from $1,600 2024-04-19
Mattermost Mobile MEDIUM 6.5
CVE-2024-3872

Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an una…

Fix: after 2.13.0
Fix from $1,600 2024-04-16
Lollms Webui HIGH 7.5
CVE-2024-1569

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_co…

Patch available
Fix from $1,950 2024-04-16
Storage Monitoring And Reporting MEDIUM 6.5
CVE-2024-0157

Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthen…

Fix: 5.0.0.0+
Fix from $1,600 2024-04-12
Anythingllm HIGH 7.5
CVE-2024-3569

A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a …

Fix: 1.0.0+
Fix from $1,950 2024-04-10
Windows Server 2008 HIGH 7.5
CVE-2024-26215

DHCP Server Service Denial of Service Vulnerability

Fix: 10.0.14393.6897 / 10.0.17763.5696+
Fix from $1,950 2024-04-09
Windows Server 2008 HIGH 7.5
CVE-2024-26212EPSS 63%

DHCP Server Service Denial of Service Vulnerability

Fix: 10.0.14393.6897 / 10.0.17763.5696+
Fix from $1,950 2024-04-09
Mattermost Server MEDIUM 6.5
CVE-2024-28949

Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit the number of user preferences…

Fix: 8.1.11 / 9.3.3+
Fix from $1,600 2024-04-05
Unclassified MEDIUM 5.3
CVE-2024-31209

oidcc is the OpenID Connect client library for Erlang. Denial of Service (DoS) by Atom exhaustion is possible by calling `oidcc_provider_configuratio…

Patch available
Fix from $1,600 2024-04-04
Linux Kernel HIGH 7.8
CVE-2024-26723

In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix crash when adding interface under a lag There is a crash when addi…

Fix: 6.1.79 / 6.6.18+
Fix from $1,950 2024-04-03
Argo Cd MEDIUM 6.5
CVE-2024-29893

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-…

Fix: 2.8.14 / 2.9.10+
Fix from $1,600 2024-03-29
Elasticsearch HIGH 7.5
CVE-2024-23450

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node …

Fix: 7.17.19 / 8.13.0+
Fix from $1,950 2024-03-27
Common Cryptographic Architecture HIGH 7.5
CVE-2023-47150

IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handlin…

Fix: 7.5.37+
Fix from $1,950 2024-03-26
Factorytalk View MEDIUM 5.3
CVE-2024-21914

A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely wi…

Fix: 14.0+
Fix from $1,600 2024-03-25
Unclassified MEDIUM 5.3
CVE-2018-25100

The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affe…

Patch available
Fix from $1,600 2024-03-24
Unclassified HIGH 7.5
CVE-2023-5685

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically …

Mitigation only
Fix from $1,950 2024-03-22
1kr42a Firmware MEDIUM 5.3
CVE-2023-4063

Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.

Fix: 002.2349a+
Fix from $1,600 2024-03-22
Bref MEDIUM 5.3
CVE-2024-29186

Bref is an open-source project that helps users go serverless on Amazon Web Services with PHP. When Bref prior to version 2.1.17 is used with the Eve…

Fix: 2.1.17+
Fix from $1,600 2024-03-22
Tar MEDIUM 6.5
CVE-2024-28863

node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An a…

Fix: 6.2.1+
Fix from $1,600 2024-03-21
Code Embed MEDIUM 6.5
CVE-2023-49837

Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6.

Fix: after 2.3.6
Fix from $1,600 2024-03-21
Fedora HIGH 7.5
CVE-2023-50967

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Fix: after 11
Fix from $1,950 2024-03-20