Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Libgit2 HIGH 7.5
CVE-2024-24575

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i…

Fix: 1.6.5 / 1.7.2+
Fix from $1,950 2024-02-06
Toolbox MEDIUM 5.5
CVE-2024-24943

In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

Fix: 2.2+
Fix from $1,600 2024-02-06
Python Multipart HIGH 7.5
CVE-2024-24762

`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `…

Fix: 0.0.7+
Fix from $1,950 2024-02-05
Libexpat HIGH 7.5
CVE-2023-52425

libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for w…

Fix: after 2.5.0
Fix from $1,950 2024-02-04
Security Verify Access HIGH 7.5
CVE-2023-31006

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Security Verify Access HIGH 7.5
CVE-2023-30999

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Bref MEDIUM 6.5
CVE-2024-24752

Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, th…

Fix: 2.1.13+
Fix from $1,600 2024-02-01
E Ddc3.3 Firmware HIGH 7.5
CVE-2024-1014

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt th…

No fix yet
Fix from $1,950 2024-01-29
Spring Framework HIGH 7.5
CVE-2024-22233

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-servic…

Mitigation only
Fix from $1,950 2024-01-22
Mbed Tls HIGH 7.5
CVE-2024-23744

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

Fix: after 3.5.1
Fix from $1,950 2024-01-21
App Store MEDIUM 5.5
CVE-2023-6450

An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a …

Fix: 12.4.20+
Fix from $1,600 2024-01-19
MySQL MEDIUM 6.5
CVE-2024-20985

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 8.0.35 and prior and 8…

Fix: after 8.2.0
Fix from $1,600 2024-01-16
MySQL MEDIUM 6.5
CVE-2024-20977

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior …

Fix: after 8.2.0
Fix from $1,600 2024-01-16
MySQL MEDIUM 6.5
CVE-2024-20961

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 and prior …

Fix: after 8.2.0
Fix from $1,600 2024-01-16
Confluence Data Center HIGH 7.5
CVE-2023-22512EPSS 14%

This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7…

Fix: 7.19.14 / 8.5.1+
Fix from $1,950 2024-01-16
Scdbg MEDIUM 5.5
CVE-2024-0581

An Uncontrolled Resource Consumption vulnerability has been found on Sandsprite Scdbg.exe, affecting version 1.0. This vulnerability allows an attack…

Mitigation only
Fix from $1,600 2024-01-16
Emui HIGH 7.5
CVE-2023-52098

Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,950 2024-01-16
Emui HIGH 7.5
CVE-2023-52113

launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

Mitigation only
Fix from $1,950 2024-01-16
Drupal HIGH 7.5
CVE-2024-22362

Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a…

Mitigation only
Fix from $1,950 2024-01-16
Discourse HIGH 7.5
CVE-2023-48297

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead…

Fix: 3.1.4+
Fix from $1,950 2024-01-12
Cloud Foundry Deployment HIGH 7.5
CVE-2023-34061

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerabil…

Fix: after 33.5.0
Fix from $1,950 2024-01-12
Quic Go MEDIUM 6.5
CVE-2023-49295

quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a…

Fix: 0.37.7 / 0.38.2+
Fix from $1,600 2024-01-10
Engineers Online Portal MEDIUM 6.5
CVE-2024-0348

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of th…

No fix yet
Fix from $1,600 2024-01-09
.net HIGH 7.5
CVE-2024-20672

.NET Denial of Service Vulnerability

Fix: 6.0.26 / 7.0.15+
Fix from $1,950 2024-01-09
Windows 10 1507 HIGH 7.5
CVE-2024-20661

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Fix: 10.0.10240.20402 / 10.0.14393.6614+
Fix from $1,950 2024-01-09
Xwiki MEDIUM 6.5
CVE-2024-21651

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can p…

Fix: 14.10.18 / 15.5.3+
Fix from $1,600 2024-01-09
Evo Nano Drone Firmware MEDIUM 5.7
CVE-2023-50121

Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).

No fix yet
Fix from $1,600 2024-01-06
Encodedid\ HIGH 7.5
CVE-2024-0241

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacke…

Fix: 1.0.0+
Fix from $1,950 2024-01-04
Ric Plt E2mgr HIGH 7.7
CVE-2023-42358

An issue was discovered in O-RAN Software Community ric-plt-e2mgr in the G-Release environment, allows remote attackers to cause a denial of service …

No fix yet
Fix from $1,950 2024-01-03
Yasm MEDIUM 5.5
CVE-2023-49555

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nas…

No fix yet
Fix from $1,600 2024-01-03