Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Jose MEDIUM 5.3
CVE-2022-36083

JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto in Node.js, Browser, Cloudfla…

Fix: 1.28.2 / 2.0.6+
Fix from $1,600 2022-09-07
Helm HIGH 7.5
CVE-2022-36049

Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allow…

Fix: 0.23.0 / 0.32.0+
Fix from $1,950 2022-09-07
Shescape HIGH 7.5
CVE-2022-36064

Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to esca…

Fix: 1.5.10+
Fix from $1,950 2022-09-06
Debian Linux HIGH 7.5
CVE-2020-29260

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup().

Patch available
Fix from $1,950 2022-09-02
Apq8096au Firmware MEDIUM 5.5
CVE-2022-22101

Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto

Mitigation only
Fix from $1,600 2022-09-02
Openshift Container Platform MEDIUM 6.3
CVE-2022-1677

In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of th…

Patch available
Fix from $1,600 2022-09-01
Libraw MEDIUM 5.5
CVE-2020-35534

In LibRaw, there is a memory corruption vulnerability within the "crxFreeSubbandData()" function (libraw\src\decoders\crx.cpp) when processing cr3 fi…

Patch available
Fix from $1,600 2022-09-01
Helm MEDIUM 6.5
CVE-2022-36055

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided by the CNCF, identified input …

Fix: 3.9.4+
Fix from $1,600 2022-09-01
D0 06dd1 Firmware HIGH 7.5
CVE-2022-2004

AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to prevent access from DirectSoft and …

Fix: 2.72+
Fix from $1,950 2022-08-31
Build Of Quarkus HIGH 7.5
CVE-2022-1259

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of servic…

Fix: after 2.2.17
Fix from $1,950 2022-08-31
Cimg MEDIUM 5.5
CVE-2022-1325

A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy header field values it is possible…

Fix: 3.1.0+
Fix from $1,600 2022-08-31
Nitrado.js HIGH 7.5
CVE-2022-36034

nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been …

Fix: 0.2.5+
Fix from $1,950 2022-08-29
Openshift Container Platform MEDIUM 6.5
CVE-2022-0669

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_IN…

Fix: 22.03+
Fix from $1,600 2022-08-29
Linux Kernel MEDIUM 5.5
CVE-2021-3669

A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to…

Fix: 2.7+
Fix from $1,600 2022-08-26
Rizin MEDIUM 5.5
CVE-2021-4022

A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted binarygets analysed by rizin…

Fix: after 0.3.1
Fix from $1,600 2022-08-25
Vtk HIGH 7.5
CVE-2021-42521

There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the re…

Fix: after 9.0.0
Fix from $1,950 2022-08-25
Amq Broker MEDIUM 5.3
CVE-2021-4040

A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. T…

Fix: 2.19.1 / 7.10.0+
Fix from $1,600 2022-08-24
Node Opcua HIGH 7.5
CVE-2022-24375

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sen…

Fix: 2.74.0+
Fix from $1,950 2022-08-24
Better Messages MEDIUM 6.5
CVE-2022-33142

Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10.57 at WordPress.

Fix: 1.9.10.58+
Fix from $1,600 2022-08-23
Debian Linux HIGH 7.5
CVE-2021-20298

A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all me…

Fix: after 2.5.7
Fix from $1,950 2022-08-23
Storage MEDIUM 6.5
CVE-2021-3670

MaxQueryDuration not honoured in Samba AD DC LDAP

Fix: 4.16.0+
Fix from $1,600 2022-08-23
Fuse HIGH 7.5
CVE-2021-3690

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cau…

Fix: 2.0.40 / 2.2.10+
Fix from $1,950 2022-08-23
Linux Kernel MEDIUM 5.5
CVE-2021-3759

A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function…

Mitigation only
Fix from $1,600 2022-08-23
Linux Kernel MEDIUM 5.5
CVE-2021-3764

A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a denial of service. The vulnerabi…

Fix: after 5.14.20
Fix from $1,600 2022-08-23
Pngdec MEDIUM 6.5
CVE-2022-35013

PNGDec commit 8abf6be was discovered to contain a FPE via SaveBMP at /linux/main.cpp.

No fix yet
Fix from $1,600 2022-08-16
Fedora HIGH 7.5
CVE-2022-38150

In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1…

Mitigation only
Fix from $1,950 2022-08-11
Windows 10 HIGH 7.5
CVE-2022-35769

Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability

No fix yet
Fix from $1,950 2022-08-09
Azure Site Recovery Vmware To Azure MEDIUM 6.2
CVE-2022-35776

Azure Site Recovery Denial of Service Vulnerability

Fix: 9.50.6419.1+
Fix from $1,600 2022-08-09
Windows 10 HIGH 7.5
CVE-2022-34701

Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability

No fix yet
Fix from $1,950 2022-08-09
Elements Endpoint Detection And Response HIGH 7.5
CVE-2022-28880

A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is…

Mitigation only
Fix from $1,950 2022-08-05