Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Mattermost Server HIGH 7.5
CVE-2023-5330

Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to t…

Fix: 7.8.11 / 8.0.3+
Fix from $1,950 2023-10-09
Mattermost Server MEDIUM 6.5
CVE-2023-5333

Mattermost fails to deduplicate input IDs allowing a simple user to cause the application to consume excessive resources and possibly crash by sendin…

Fix: 7.8.11 / 8.0.3+
Fix from $1,600 2023-10-09
Android MEDIUM 5.5
CVE-2023-21253

In multiple locations, there is a possible way to crash multiple system services due to resource exhaustion. This could lead to local denial of servi…

Patch available
Fix from $1,600 2023-10-06
Opentelemetry HIGH 7.5
CVE-2023-43810

OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting, generating, collecting, and e…

Fix: 0.41b0+
Fix from $1,950 2023-10-06
Emergency Responder HIGH 7.5
CVE-2023-20259

A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CP…

Mitigation only
Fix from $1,950 2023-10-04
Openshift Container Platform MEDIUM 5.3
CVE-2023-3153

A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a de…

Fix: 22.03.3 / 22.09.2+
Fix from $1,600 2023-10-04
Ar8035 Firmware HIGH 7.5
CVE-2023-33026

Transient DOS in WLAN Firmware while parsing a NAN management frame.

Mitigation only
Fix from $1,950 2023-10-03
Opcua Asyncio HIGH 7.5
CVE-2023-26151

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a re…

Fix: 0.9.96+
Fix from $1,950 2023-10-03
Mattermost MEDIUM 6.5
CVE-2023-5196

Mattermost fails to enforce character limits in all possible notification props allowing an attacker to send a really long value for a notification_p…

Fix: 7.8.10 / 8.0.2+
Fix from $1,600 2023-09-29
Catalyst 9166 Firmware HIGH 8.6
CVE-2023-20176

A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary …

Fix: 17.6.6+
Fix from $1,950 2023-09-27
MariaDB HIGH 7.5
CVE-2023-5157

A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.

Fix: 10.3.36 / 10.4.26+
Fix from $1,950 2023-09-27
Get Func Name HIGH 7.5
CVE-2023-43646

get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject…

Fix: 2.0.1+
Fix from $1,950 2023-09-27
Smp Sg 4260 Firmware MEDIUM 5.3
CVE-2023-43775

Denial-of-service vulnerability in the web server of the Eaton SMP Gateway allows attacker to potentially force an unexpected restart of the automa…

Fix: 8.0r9 / 8.1r5+
Fix from $1,600 2023-09-27
Ipados MEDIUM 6.5
CVE-2023-40441

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. Processing we…

Fix: 14.0 / 17.0+
Fix from $1,600 2023-09-27
Harmonyos CRITICAL 9.8
CVE-2023-41294

The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.

No fix yet
Fix from $2,300 2023-09-25
Not Quite Ptp MEDIUM 5.5
CVE-2023-43771

In nqptp-message-handlers.c in nqptp before 1.2.3, crafted packets received on the control port could crash the program.

Fix: 1.2.3+
Fix from $1,600 2023-09-22
Linux Protection HIGH 7.5
CVE-2023-43767

Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Ser…

Mitigation only
Fix from $1,950 2023-09-22
Rest HIGH 7.5
CVE-2023-42457

plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and prior to versions 2.0.1 and 3…

Patch available
Fix from $1,950 2023-09-21
Graphql MEDIUM 5.3
CVE-2023-26144

Versions of the package graphql from 16.3.0 and before 16.8.1 are vulnerable to Denial of Service (DoS) due to insufficient checks in the Overlapping…

Fix: 16.8.1+
Fix from $1,600 2023-09-20
Malware Fighter MEDIUM 5.5
CVE-2020-24089

An issue was discovered in ImfHpRegFilter.sys in IOBit Malware Fighter version 8.0.2, allows local attackers to cause a denial of service (DoS).

Mitigation only
Fix from $1,600 2023-09-20
Ekorrci Firmware MEDIUM 6.5
CVE-2022-47556

Uncontrolled resource consumption in ekorRCI, allowing an attacker with low-privileged access to the web server to send continuous legitimate web req…

Mitigation only
Fix from $1,600 2023-09-19
Client Security HIGH 7.5
CVE-2023-42521

Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15…

Mitigation only
Fix from $1,950 2023-09-18
Client Security HIGH 7.5
CVE-2023-42522

Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client…

Mitigation only
Fix from $1,950 2023-09-18
Client Security HIGH 7.5
CVE-2023-42523

Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSec…

Mitigation only
Fix from $1,950 2023-09-18
Client Security HIGH 7.5
CVE-2023-42520

Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15…

Mitigation only
Fix from $1,950 2023-09-18
Client Security HIGH 7.5
CVE-2023-42526

Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Securit…

Mitigation only
Fix from $1,950 2023-09-18
Glib HIGH 7.5
CVE-2023-29499

A flaw was found in GLib. GVariant deserialization fails to validate that the input conforms to the expected format, leading to denial of service.

Fix: 2.74.4+
Fix from $1,950 2023-09-14
Glib MEDIUM 5.5
CVE-2023-32611

A flaw was found in GLib. GVariant deserialization is vulnerable to a slowdown issue where a crafted GVariant can cause excessive processing, leading…

Fix: 2.74.2+
Fix from $1,600 2023-09-14
Glib HIGH 7.5
CVE-2023-32636

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation adde…

Fix: 2.74.4+
Fix from $1,950 2023-09-14
Glib MEDIUM 5.5
CVE-2023-32665

A flaw was found in GLib. GVariant deserialization is vulnerable to an exponential blowup issue where a crafted GVariant can cause excessive processi…

Fix: 2.74.4+
Fix from $1,600 2023-09-14