Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Ua .net Standard Stack HIGH 7.5
CVE-2022-29866

OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontro…

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Foundry Multipass CRITICAL 9.1
CVE-2022-27889

The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. …

Fix: 3.647.0+
Fix from $2,300 2022-06-14
Argo Events HIGH 7.5
CVE-2022-31054

Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the …

Fix: 1.7.1+
Fix from $1,950 2022-06-13
Envoy HIGH 7.5
CVE-2022-29225

Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer be…

Fix: 1.22.1+
Fix from $1,950 2022-06-09
Debian Linux MEDIUM 5.5
CVE-2022-31030

containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause th…

Fix: 1.5.13 / 1.6.6+
Fix from $1,600 2022-06-09
Cri O HIGH 7.5
CVE-2022-1708

A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync reque…

Fix: 1.19.7 / 1.20.8+
Fix from $1,950 2022-06-07
Minio HIGH 7.5
CVE-2022-31028

MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-0…

Fix: 2022-06-02t02-11-04z+
Fix from $1,950 2022-06-07
Powerstoreos HIGH 7.5
CVE-2022-22556

Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unauthenticated attacker could pot…

Fix: 2.1.0.0 / 2.1.1.0+
Fix from $1,950 2022-06-02
Mattermost Server MEDIUM 6.5
CVE-2022-1982

Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG atta…

Fix: 6.3.8 / 6.4.3+
Fix from $1,600 2022-06-02
Play Framework HIGH 7.5
CVE-2022-31018

Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's…

Fix: after 2.8.15
Fix from $1,950 2022-06-02
Curl HIGH 7.5
CVE-2022-27781

libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an er…

Fix: 7.83.1+
Fix from $1,950 2022-06-02
Compactlogix 5380 Firmware HIGH 8.6
CVE-2022-1797

A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix …

Fix: 33.011 / 34.011+
Fix from $1,950 2022-06-02
Integration MEDIUM 5.9
CVE-2021-3629

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a deni…

Fix: 2.0.40 / 2.2.11+
Fix from $1,600 2022-05-24
Tensorflow MEDIUM 5.5
CVE-2022-29202

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.ragged.consta…

Fix: 2.6.4 / 2.7.2+
Fix from $1,600 2022-05-20
Go Ethereum MEDIUM 5.9
CVE-2022-29177

Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node, if configured to use high ve…

Fix: 1.10.17+
Fix from $1,600 2022-05-20
Simatic Cp 442 1 Rna Firmware MEDIUM 6.5
CVE-2022-27640

A vulnerability has been identified in SIMATIC CP 442-1 RNA (All versions < V1.5.18), SIMATIC CP 443-1 RNA (All versions < V1.5.18). The affected dev…

Fix: 1.5.18+
Fix from $1,600 2022-05-20
Ua Java HIGH 7.5
CVE-2022-30551

OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust a…

Patch available
Fix from $1,950 2022-05-20
Virtual Gpu MEDIUM 5.5
CVE-2022-28191

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an …

Fix: 11.8 / 13.3+
Fix from $1,600 2022-05-17
Software Guard Extensions MEDIUM 5.5
CVE-2021-33135

Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of servic…

Fix: after 2.14
Fix from $1,600 2022-05-12
Organizr HIGH 7.5
CVE-2022-1699

Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack fo…

Fix: 2.1.2000+
Fix from $1,950 2022-05-12
Tomcat HIGH 7.5
CVE-2022-29885EPSS 73%

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor in…

Fix: after 10.0.20
Fix from $1,950 2022-05-12
Fedora HIGH 7.5
CVE-2022-29145

.NET and Visual Studio Denial of Service Vulnerability

Fix: 16.9.21 / 16.11.14+
Fix from $1,950 2022-05-10
Fedora HIGH 7.5
CVE-2022-29117EPSS 5%

.NET and Visual Studio Denial of Service Vulnerability

Fix: after 16.0.11
Fix from $1,950 2022-05-10
Desigo Pxc5 Firmware MEDIUM 6.5
CVE-2022-24040

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All v…

Fix: 01.21.142.4-18 / 01.21.142.5-22+
Fix from $1,600 2022-05-10
Hawk HIGH 7.5
CVE-2022-29167

Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic verification of the requ…

Fix: 9.0.1+
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-29480

On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-28691

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-28701

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase…

Mitigation only
Fix from $1,950 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-27181

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-27182

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, when BIG-IP packet filters …

No fix yet
Fix from $1,600 2022-05-05