Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Unite MEDIUM 5.5
CVE-2023-25179

Uncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentially enabl…

Fix: after 17
Fix from $1,600 2023-05-10
Smart Campus MEDIUM 5.5
CVE-2022-46645

Uncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potentially …

Fix: 9.9+
Fix from $1,600 2023-05-10
Connect M MEDIUM 5.5
CVE-2022-41801

Uncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially en…

Fix: 1.82+
Fix from $1,600 2023-05-10
Octopus Server MEDIUM 5.5
CVE-2022-4008

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

Fix: 2022.3.11043 / 2022.4.8401+
Fix from $1,600 2023-05-10
Mq Appliance MEDIUM 5.5
CVE-2023-22874

IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.

Fix: 9.3.0.5 / 9.3.2+
Fix from $1,600 2023-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2023-24594

When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.   N…

Mitigation only
Fix from $1,600 2023-05-03
Modsecurity HIGH 7.5
CVE-2023-28882

Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a seg…

Fix: 3.0.9+
Fix from $1,950 2023-04-28
Jerryscript MEDIUM 5.5
CVE-2023-30406

Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component ecma_find_named_property at /base/ecma-helpers.c.

No fix yet
Fix from $1,600 2023-04-24
Jerryscript MEDIUM 5.5
CVE-2023-30408

Jerryscript commit 1a2c047 was discovered to contain a segmentation violation via the component build/bin/jerry.

No fix yet
Fix from $1,600 2023-04-24
Rnp MEDIUM 5.3
CVE-2023-29479

Ribose RNP before 0.16.3 may hang when the input is malformed.

Fix: 0.16.3+
Fix from $1,600 2023-04-24
Starlette HIGH 7.5
CVE-2023-30798

There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify an…

Fix: 0.25.0+
Fix from $1,950 2023-04-21
Super Clean MEDIUM 5.5
CVE-2023-27652

An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field…

No fix yet
Fix from $1,600 2023-04-20
Onos HIGH 7.5
CVE-2022-24035

An issue was discovered in ONOS 2.5.1. The purge-requested intent remains on the list, but it does not respond to changes in topology (e.g., link fai…

No fix yet
Fix from $1,950 2023-04-20
Onos MEDIUM 6.5
CVE-2022-24109

An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a duplicate intent with a differ…

No fix yet
Fix from $1,600 2023-04-20
M Files Server HIGH 7.5
CVE-2023-0383

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

Fix: 23.4.12528.1+
Fix from $1,950 2023-04-20
M Files Server HIGH 7.5
CVE-2023-0384

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a …

Fix: 23.4.12528.1+
Fix from $1,950 2023-04-20
Android MEDIUM 5.0
CVE-2023-21090

In parseUsesPermission of ParsingPackageUtils.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of serv…

Patch available
Fix from $1,600 2023-04-19
Jetty MEDIUM 5.3
CVE-2023-26048

Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) th…

Fix: 9.4.51 / 10.0.14+
Fix from $1,600 2023-04-18
Weblogic Server HIGH 7.5
CVE-2023-21996

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are …

Mitigation only
Fix from $1,950 2023-04-18
Weblogic Server HIGH 7.5
CVE-2023-21964

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3…

Mitigation only
Fix from $1,950 2023-04-18
Health Sciences Inform MEDIUM 5.3
CVE-2023-21925

Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are aff…

Fix: 6.3.1.3+
Fix from $1,600 2023-04-18
Dogecoin CRITICAL 9.8
CVE-2023-30769

Vulnerability discovered is related to the peer-to-peer (p2p) communications, attackers can craft consensus messages, send it to individual nodes and…

Fix: 1.14.6+
Fix from $2,300 2023-04-17
Dir 819 Firmware HIGH 7.5
CVE-2022-40946EPSS 8%

On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via the sys_token parameter in a c…

No fix yet
Fix from $1,950 2023-04-16
Openbmc HIGH 7.5
CVE-2021-39295

In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.

No fix yet
Fix from $1,950 2023-04-15
Traefik HIGH 7.5
CVE-2023-29013

Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer for deploying microservices. There is a vulnerability in Go when parsin…

Fix: 2.9.10+
Fix from $1,950 2023-04-14
Poweramp HIGH 7.5
CVE-2023-27643

An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue …

No fix yet
Fix from $1,950 2023-04-14
Tikv HIGH 7.5
CVE-2023-30635

TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error) upon an attempt to get a timestamp from the Placement Driver.

No fix yet
Fix from $1,950 2023-04-13
Spring Framework MEDIUM 6.5
CVE-2023-20863

In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression …

Fix: 5.2.24 / 5.3.27+
Fix from $1,600 2023-04-13
Wireshark MEDIUM 6.5
CVE-2023-1994

GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file

Fix: 3.6.13 / 4.0.5+
Fix from $1,600 2023-04-12
Cloudeos HIGH 7.5
CVE-2023-24545

On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by se…

Fix: 4.26.9m / 4.27.8m+
Fix from $1,950 2023-04-12