Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Cybozu Remote Service MEDIUM 6.5
CVE-2023-46278

Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated attacker to consume huge storag…

Fix: 4.1.2+
Fix from $1,600 2023-11-01
Tapo C100 Firmware MEDIUM 6.5
CVE-2023-39610

An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a cr…

Fix: after 1.1.15
Fix from $1,600 2023-10-31
Lightstrip Firmware HIGH 7.5
CVE-2023-45955

An issue discovered in Nanoleaf Light strip v3.5.10 allows attackers to cause a denial of service via crafted write binding attribute commands.

Mitigation only
Fix from $1,950 2023-10-31
Jbig2dec MEDIUM 6.5
CVE-2023-46361

Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.

No fix yet
Fix from $1,600 2023-10-31
Led Strip Firmware HIGH 7.5
CVE-2023-45956

An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.

Mitigation only
Fix from $1,950 2023-10-30
Android HIGH 7.5
CVE-2023-21339

In Minikin, there is a possible way to trigger ANR by showing a malicious message due to resource exhaustion. This could lead to remote denial of ser…

Fix: 14.0+
Fix from $1,950 2023-10-30
Elasticsearch HIGH 7.5
CVE-2023-31418

An issue has been identified with how Elasticsearch handled incoming requests on the HTTP layer. An unauthenticated user could force an Elasticsearch…

Fix: after 8.8.2
Fix from $1,950 2023-10-26
Ipados MEDIUM 5.3
CVE-2023-40408

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1, watchOS 10.1, iOS 16.7.2…

Fix: 10.1 / 16.7.2+
Fix from $1,600 2023-10-25
Firefox HIGH 7.5
CVE-2023-5724

Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Fir…

Fix: 115.4 / 115.4.1+
Fix from $1,950 2023-10-25
Rabbitmq Java Client HIGH 7.5
CVE-2023-46120

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used …

Fix: 5.18.0+
Fix from $1,950 2023-10-25
Werkzeug HIGH 7.5
CVE-2023-46136

Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an up…

Fix: 2.3.8+
Fix from $1,950 2023-10-25
Pingfederate HIGH 7.5
CVE-2023-39219

PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration req…

Fix: after 11.2.6
Fix from $1,950 2023-10-25
HTTP Server HIGH 7.5
CVE-2023-43622EPSS 71%

An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP …

Fix: 2.4.58+
Fix from $1,950 2023-10-23
Openfga HIGH 7.5
CVE-2023-45810

OpenFGA is a flexible authorization/permission engine built for developers and inspired by Google Zanzibar. Affected versions of OpenFGA are vulnerab…

Fix: 1.3.4+
Fix from $1,950 2023-10-17
Discourse HIGH 7.5
CVE-2023-44388

Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result …

Fix: after 3.1.1
Fix from $1,950 2023-10-16
Graphql HIGH 7.5
CVE-2023-40180

silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execu…

Fix: 3.8.2 / 4.1.3+
Fix from $1,950 2023-10-16
Gpac MEDIUM 5.5
CVE-2023-5595

Denial of Service in GitHub repository gpac/gpac prior to 2.3.0-DEV.

Fix: 2.3.0+
Fix from $1,600 2023-10-16
Security Verify Access Oidc Provider HIGH 7.5
CVE-2022-43740

IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Forc…

Patch available
Fix from $1,950 2023-10-14
Commerce MEDIUM 5.3
CVE-2023-38251

Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncont…

Mitigation only
Fix from $1,600 2023-10-13
Junos HIGH 7.5
CVE-2023-36841

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series…

Fix: 20.4+
Fix from $1,950 2023-10-12
Clustered Data Ontap HIGH 7.5
CVE-2023-27314

ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote …

Fix: 9.8+
Fix from $1,950 2023-10-12
Vpn HIGH 7.5
CVE-2023-25774

A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network …

No fix yet
Fix from $1,950 2023-10-12
Windows 10 HIGH 7.5
CVE-2023-36606EPSS 67%

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10
Windows Server 2008 HIGH 7.5
CVE-2023-36703

DHCP Server Service Denial of Service Vulnerability

Patch available
Fix from $1,950 2023-10-10
Windows 10 1507 HIGH 7.5
CVE-2023-36579

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10
Windows 10 1507 HIGH 7.5
CVE-2023-36431

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

Fix: 10.0.10240.20232 / 10.0.14393.6351+
Fix from $1,950 2023-10-10
.net HIGH 7.5
CVE-2023-36435EPSS 5%

Microsoft QUIC Denial of Service Vulnerability

Fix: 10.0.22000.2538 / 10.0.22621.2428+
Fix from $1,950 2023-10-10
Jenkins HIGH 7.5
CVE-2023-36478

Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an i…

Fix: 2.414.3 / 2.428+
Fix from $1,950 2023-10-10
Caddy HIGH 7.5
CVE-2023-44487 KEVEPSS 100%

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploite…

Fix: 0.17.0 / 1.20.10+
Fix from $1,950 2023-10-10
Enterprise Linux MEDIUM 5.5
CVE-2023-43786

A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available…

Fix: 1.8.7+
Fix from $1,600 2023-10-10