Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Yasm MEDIUM 5.5
CVE-2023-49557

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.…

No fix yet
Fix from $1,600 2024-01-03
Mjs HIGH 7.5
CVE-2023-49550

An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.

No fix yet
Fix from $1,950 2024-01-02
Open5gs MEDIUM 5.9
CVE-2023-50019

An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handli…

Patch available
Fix from $1,600 2024-01-02
Open5gs HIGH 7.5
CVE-2023-50020

An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.

Patch available
Fix from $1,950 2024-01-02
Libredwg HIGH 7.5
CVE-2023-26157

Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pag…

Fix: 0.12.5.6384+
Fix from $1,950 2024-01-02
Grackle HIGH 7.5
CVE-2023-50730

Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification requires that GraphQL fragments must…

Fix: 0.18.0+
Fix from $1,950 2023-12-22
Grails HIGH 7.5
CVE-2023-46131

Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or…

Fix: 3.3.17 / 4.1.3+
Fix from $1,950 2023-12-21
Astro HIGH 7.5
CVE-2023-50249

Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry'…

Fix: 7.87.0+
Fix from $1,950 2023-12-20
Bcu 500 Firmware HIGH 7.5
CVE-2023-50707

Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device.

No fix yet
Fix from $1,950 2023-12-20
Superset MEDIUM 6.5
CVE-2023-46104

Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.…

Fix: 2.1.3 / 3.0.1+
Fix from $1,600 2023-12-19
Opc HIGH 7.5
CVE-2023-41151

An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the…

Fix: after 6.20.1
Fix from $1,950 2023-12-14
Quiche MEDIUM 5.3
CVE-2023-6193

quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resou…

Fix: after 0.19.0
Fix from $1,600 2023-12-12
Gc A22w Cw Firmware HIGH 7.5
CVE-2023-41963

Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packe…

Mitigation only
Fix from $1,950 2023-12-12
Gc A22w Cw Firmware HIGH 7.5
CVE-2023-49140

Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially cra…

Mitigation only
Fix from $1,950 2023-12-12
Gc A22w Cw Firmware HIGH 7.5
CVE-2023-49143

Denial-of-service (DoS) vulnerability exists in rfe service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packe…

Mitigation only
Fix from $1,950 2023-12-12
Gc A22w Cw Firmware HIGH 7.5
CVE-2023-49713

Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted p…

Mitigation only
Fix from $1,950 2023-12-12
Mattermost Server MEDIUM 6.5
CVE-2023-49809

Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoi…

Fix: after 9.1.0
Fix from $1,600 2023-12-12
Mattermost Server HIGH 7.5
CVE-2023-45847

Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to send a specially crafted requ…

Fix: after 9.2.1
Fix from $1,950 2023-12-12
Nuxt Api Party HIGH 7.5
CVE-2023-49800

`nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no f…

Fix: after 0.21.3
Fix from $1,950 2023-12-09
Nae55 Firmware HIGH 7.5
CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC e…

Fix: 12.0.4+
Fix from $1,950 2023-12-07
Ninja Forms MEDIUM 5.3
CVE-2023-35909

Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to …

Fix: 3.6.26+
Fix from $1,600 2023-12-07
Appointment Scheduler HIGH 7.5
CVE-2023-48840

A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
Availability Booking Calendar HIGH 7.5
CVE-2023-48831

A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
Time Slots Booking Calendar HIGH 7.5
CVE-2023-48833

A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
Car Rental Script HIGH 7.5
CVE-2023-48834

A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
Boring MEDIUM 5.3
CVE-2023-6180

The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by res…

Mitigation only
Fix from $1,600 2023-12-05
Networking Os10 HIGH 7.5
CVE-2023-39248

Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Service) vulnerability, when switche…

Mitigation only
Fix from $1,950 2023-12-05
Jwx MEDIUM 5.3
CVE-2023-49290

lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p2c parameter set too high in …

Fix: 1.2.27 / 2.0.18+
Fix from $1,600 2023-12-05
Traefik HIGH 7.5
CVE-2023-47633

Traefik is an open source HTTP reverse proxy and load balancer. The traefik docker container uses 100% CPU when it serves as its own backend, which i…

Fix: after 2.10.5
Fix from $1,950 2023-12-04
Db2 HIGH 7.5
CVE-2023-40692

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, 11.5 is vulnerable to denial of service under extreme stress conditions…

Patch available
Fix from $1,950 2023-12-04