Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Is.js HIGH 7.5
CVE-2020-26302

is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression …

Fix: after 0.9.0
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-42929

If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart…

Fix: 102.4 / 106.0+
Fix from $1,600 2022-12-22
Enumstringvalues HIGH 7.5
CVE-2020-36620

A vulnerability was found in Brondahl EnumStringValues up to 4.0.0. It has been declared as problematic. This vulnerability affects the function GetS…

Fix: 4.0.1+
Fix from $1,950 2022-12-21
Harmonyos HIGH 7.5
CVE-2022-46315

The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability.

Fix: 2.1+
Fix from $1,950 2022-12-20
Bm78 Firmware HIGH 7.5
CVE-2022-46399

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.

No fix yet
Fix from $1,950 2022-12-19
Helm HIGH 7.5
CVE-2022-23524

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, r…

Fix: 3.10.3+
Fix from $1,950 2022-12-15
6gk5204 0ba00 2mb2 Firmware MEDIUM 5.5
CVE-2022-46351

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204R…

Fix: 3.2.7+
Fix from $1,600 2022-12-13
6gk5204 0ba00 2mb2 Firmware HIGH 7.5
CVE-2022-46352

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204R…

Fix: 3.2.7+
Fix from $1,950 2022-12-13
Siprotec 5 6md85 Firmware MEDIUM 5.3
CVE-2022-45044

A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.50), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP…

Mitigation only
Fix from $1,600 2022-12-13
Cloud Foundation MEDIUM 5.3
CVE-2022-31698EPSS 48%

The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vC…

Mitigation only
Fix from $1,600 2022-12-13
Android MEDIUM 5.5
CVE-2022-20482

In createNotificationChannel of NotificationManager.java, there is a possible way to make the device unusable and require factory reset due to resour…

Mitigation only
Fix from $1,600 2022-12-13
M2u75a Firmware HIGH 7.5
CVE-2022-43780

Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.

Fix: 003.2237a+
Fix from $1,950 2022-12-12
Protobuf Java HIGH 7.5
CVE-2022-3509

A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can …

Fix: 3.16.3 / 3.19.6+
Fix from $1,950 2022-12-12
Protobuf Java HIGH 7.5
CVE-2022-3510

A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 an…

Fix: 3.16.3 / 3.19.6+
Fix from $1,950 2022-12-12
Sd Wan HIGH 7.5
CVE-2022-37907

A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted sy…

Fix: 6.5.4.22 / 8.6.0.17+
Fix from $1,950 2022-12-12
Pagewide 352dw J6u57a Firmware HIGH 7.5
CVE-2022-2794

Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.

Fix: 2228b+
Fix from $1,950 2022-12-12
Futuresmart 5 CRITICAL 9.8
CVE-2021-3821

A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service …

Fix: 5.3+
Fix from $2,300 2022-12-12
Ata 190 Firmware MEDIUM 6.5
CVE-2022-20691

A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthentica…

Fix: 11.2.2 / 12.0.1+
Fix from $1,600 2022-12-12
Libp2p HIGH 7.5
CVE-2022-23492

go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted res…

Fix: 0.18.0+
Fix from $1,950 2022-12-08
Containerd MEDIUM 6.5
CVE-2022-23471

containerd is an open source container runtime. A bug was found in containerd's CRI implementation where a user can exhaust memory on the host. In th…

Fix: 1.5.16 / 1.6.12+
Fix from $1,600 2022-12-07
Libp2p HIGH 7.5
CVE-2022-23486

libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a vic…

Fix: 0.45.1+
Fix from $1,950 2022-12-07
Libp2p HIGH 7.5
CVE-2022-23487

js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted…

Fix: 0.38.0+
Fix from $1,950 2022-12-07
Cybozu Remote Service HIGH 7.5
CVE-2022-44608

Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storag…

Fix: after 4.0.3
Fix from $1,950 2022-12-07
Debian Linux HIGH 7.5
CVE-2022-30122

A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.

Fix: 2.0.9.1 / 2.1.4.1+
Fix from $1,950 2022-12-05
Connect Secure HIGH 7.5
CVE-2022-35254

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R1…

Fix: 9.1+
Fix from $1,950 2022-12-05
Nextcloud Server MEDIUM 5.3
CVE-2022-41968

Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writin…

Fix: 23.0.10 / 24.0.5+
Fix from $1,600 2022-12-01
Line HIGH 7.5
CVE-2022-41568

LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.

Fix: 12.17.0+
Fix from $1,950 2022-11-29
Nextcloud Enterprise Server MEDIUM 6.5
CVE-2022-39346

Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could…

Fix: 22.2.10 / 23.0.7+
Fix from $1,600 2022-11-25
Fedora MEDIUM 5.5
CVE-2022-45873

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_e…

Fix: after 251
Fix from $1,600 2022-11-23
Xwiki MEDIUM 5.3
CVE-2022-41932

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new …

Fix: 13.10.8 / 14.4.2+
Fix from $1,600 2022-11-23