Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Ceph Storage MEDIUM 6.5
CVE-2023-0056

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated r…

Mitigation only
Fix from $1,600 2023-03-23
Spring Framework MEDIUM 6.5
CVE-2023-20861

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user…

Fix: after 6.0.6
Fix from $1,600 2023-03-23
Radare2 HIGH 7.5
CVE-2023-1605

Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.

Fix: 5.8.6+
Fix from $1,950 2023-03-23
Gophish HIGH 7.5
CVE-2022-45003

Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.

Fix: after 0.12.1
Fix from $1,950 2023-03-22
Windows 10 1507 MEDIUM 5.5
CVE-2023-24862

Windows Secure Channel Denial of Service Vulnerability

Fix: 10.0.10240.19805 / 10.0.14393.5786+
Fix from $1,600 2023-03-14
Windows 10 1507 MEDIUM 6.5
CVE-2023-23411

Windows Hyper-V Denial of Service Vulnerability

Fix: 10.0.10240.19805 / 10.0.14393.5786+
Fix from $1,600 2023-03-14
Office Online Server MEDIUM 6.5
CVE-2023-23396

Microsoft Excel Denial of Service Vulnerability

Patch available
Fix from $1,600 2023-03-14
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-27270

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has mult…

Mitigation only
Fix from $1,600 2023-03-14
Netweaver Application Server Abap MEDIUM 6.5
CVE-2023-25618

SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, has mult…

Mitigation only
Fix from $1,600 2023-03-14
Rack HIGH 7.5
CVE-2023-27530

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an at…

Fix: 2.0.9.3 / 2.1.4.3+
Fix from $1,950 2023-03-10
GitLab MEDIUM 5.3
CVE-2023-1072

An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all ver…

Fix: 15.7.8 / 15.8.4+
Fix from $1,600 2023-03-09
Crossplane Runtime HIGH 7.5
CVE-2023-27483

crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. An out of memory panic vulnera…

Fix: 0.19.2+
Fix from $1,950 2023-03-09
Fortirecorder Firmware HIGH 7.5
CVE-2022-41333EPSS 7%

An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanis…

Fix: after 6.4.3
Fix from $1,950 2023-03-07
Openstack Platform MEDIUM 6.5
CVE-2022-3277

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security gr…

Fix: 18.6.0 / 19.5.0+
Fix from $1,600 2023-03-06
Manageengine Assetexplorer HIGH 7.5
CVE-2023-26601EPSS 34%

Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 1400…

Fix: 6.9 / 14.0+
Fix from $1,950 2023-03-06
Moodle HIGH 7.5
CVE-2021-36395

In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion denial of service.

Fix: 3.9.8 / 3.10.5+
Fix from $1,950 2023-03-06
OpenBSD HIGH 7.5
CVE-2023-27567

In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.

Patch available
Fix from $1,950 2023-03-03
Xwiki HIGH 7.5
CVE-2023-26470

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make the farm unusable by a…

Fix: 14.0+
Fix from $1,950 2023-03-02
Storagegrid HIGH 7.5
CVE-2022-38734

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vulnerability. A successful explo…

Fix: 11.6.0.8+
Fix from $1,950 2023-03-02
Nexus Dashboard HIGH 7.5
CVE-2023-20014

A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of servi…

Fix: 2.3+
Fix from $1,950 2023-03-01
Go HIGH 7.5
CVE-2022-41724

Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients…

Fix: 1.19.6+
Fix from $1,950 2023-02-28
A200 Firmware HIGH 7.5
CVE-2023-23689

Dell PowerScale nodes A200, A2000, H400, H500, H600, H5600, F800, F810 integrated hardware management software contains an uncontrolled resource cons…

Patch available
Fix from $1,950 2023-02-28
Android MEDIUM 5.5
CVE-2022-20455

In addAutomaticZenRule of ZenModeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local d…

Mitigation only
Fix from $1,600 2023-02-28
Ipados HIGH 7.5
CVE-2023-23524

A denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS 16.3.2, iOS 16.3.1 and iPadOS 16.3.1, watchOS 9.3…

Fix: 9.3.1 / 13.2.1+
Fix from $1,950 2023-02-27
Lite Web Server HIGH 7.5
CVE-2023-26104

All versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control cha…

No fix yet
Fix from $1,950 2023-02-25
Nextcloud Server MEDIUM 6.5
CVE-2023-25816

Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A u…

Fix: 25.0.3+
Fix from $1,600 2023-02-25
Jetwave 2212g Firmware MEDIUM 6.5
CVE-2023-23296

Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.

Fix: 1.5 / 1.6+
Fix from $1,600 2023-02-23
Debian Linux MEDIUM 6.5
CVE-2023-23009

Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrect selec…

Patch available
Fix from $1,600 2023-02-21
PHP HIGH 7.5
CVE-2023-0662

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consump…

Fix: 8.0.28 / 8.1.16+
Fix from $1,950 2023-02-16
Django HIGH 7.5
CVE-2023-24580EPSS 63%

An issue was discovered in the Multipart Request Parser in Django 3.2 before 3.2.18, 4.0 before 4.0.10, and 4.1 before 4.1.7. Passing certain inputs …

Fix: 3.2.18 / 4.0.10+
Fix from $1,950 2023-02-15