Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Integration Camel K HIGH 7.5
CVE-2022-2053

When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementat…

Fix: 2.2.19+
Fix from $1,950 2022-08-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-35236

In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server,…

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,950 2022-08-04
Nginx Instance Manager MEDIUM 6.5
CVE-2022-35241

In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resou…

Fix: 2.3.1+
Fix from $1,600 2022-08-04
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-33203

In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent…

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,950 2022-08-04
V8n HIGH 7.5
CVE-2022-35923

v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowerc…

Fix: 1.5.1+
Fix from $1,950 2022-08-02
Fedora HIGH 7.5
CVE-2022-35922

Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memo…

Fix: 0.26.5+
Fix from $1,950 2022-08-01
Contracts MEDIUM 5.3
CVE-2022-35915

OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbo…

Fix: 4.7.2+
Fix from $1,600 2022-08-01
Juniper HIGH 7.5
CVE-2022-31173

Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. Thi…

Fix: 0.15.10+
Fix from $1,950 2022-08-01
Twinsoft HIGH 7.5
CVE-2021-22642

An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.

Fix: 1.46 / 12.4+
Fix from $1,950 2022-07-28
Mxnet HIGH 7.5
CVE-2022-24294

A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug coul…

Fix: 1.9.1+
Fix from $1,950 2022-07-24
H96 Pro Plus Firmware HIGH 7.5
CVE-2020-21405

An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk

No fix yet
Fix from $1,950 2022-07-20
Pexip Infinity HIGH 7.5
CVE-2022-27937

Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.

Fix: 27.3+
Fix from $1,950 2022-07-17
Mattermost MEDIUM 6.5
CVE-2022-2406

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenti…

Fix: after 6.5.1
Fix from $1,600 2022-07-14
Kubeedge MEDIUM 6.5
CVE-2022-31075

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31078

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31079

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31080

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge HIGH 7.5
CVE-2022-31073

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,950 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31074

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Control For Beaglebone HIGH 7.5
CVE-2022-30791

In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections…

Fix: 4.5.0.0 / 4.6.0.0+
Fix from $1,950 2022-07-11
Control For Beaglebone HIGH 7.5
CVE-2022-30792

In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communicati…

Fix: 4.5.0.0 / 4.6.0.0+
Fix from $1,950 2022-07-11
Smart Software Manager On Prem MEDIUM 6.5
CVE-2022-20808

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS…

Fix: 8-202112+
Fix from $1,600 2022-07-06
Fedora HIGH 7.5
CVE-2022-31129

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an ine…

Fix: 2.29.4+
Fix from $1,950 2022-07-06
Quic Go HIGH 7.5
CVE-2022-30591

quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTT…

Fix: after 0.27.0
Fix from $1,950 2022-07-06
Jboss Aerogear HIGH 7.5
CVE-2014-3648

The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is use…

Mitigation only
Fix from $1,950 2022-07-01
Rsshub HIGH 7.5
CVE-2022-31110

RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to the `filter` and `filterout`…

Fix: 2022-06-21+
Fix from $1,950 2022-06-29
Systemds HIGH 7.5
CVE-2022-26477

The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered wi…

Fix: after 2.2.1
Fix from $1,950 2022-06-27
Argo Cd MEDIUM 6.5
CVE-2022-31016

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption…

Fix: 2.1.16 / 2.2.10+
Fix from $1,600 2022-06-25
Gateway MEDIUM 5.3
CVE-2022-31803

In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all avail…

Fix: 2.3.9.38+
Fix from $1,600 2022-06-24
Ua .net Standard Stack HIGH 7.5
CVE-2022-29864

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Reso…

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16