Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-26372

On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11…

Mitigation only
Fix from $1,950 2022-05-05
Secure Firewall Threat Defense HIGH 7.5
CVE-2022-20760

A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could a…

Fix: 6.4.0.15 / 6.6.5.2+
Fix from $1,950 2022-05-03
Sonicos HIGH 7.5
CVE-2022-22275

Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially…

Fix: after 7.0.1-5030-r2007
Fix from $1,950 2022-04-27
Roboguide MEDIUM 5.9
CVE-2021-43933

The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a…

Fix: after 9.40083.00.05
Fix from $1,600 2022-04-20
Http Swagger HIGH 7.5
CVE-2022-24863

http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2…

Fix: 1.2.6+
Fix from $1,950 2022-04-18
Ios Xe MEDIUM 6.5
CVE-2022-20692

A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a deni…

Mitigation only
Fix from $1,600 2022-04-15
Debian Linux HIGH 7.5
CVE-2022-26498EPSS 16%

An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files cou…

Fix: 18.11.2+
Fix from $1,950 2022-04-15
Junos MEDIUM 6.5
CVE-2022-22191

A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent …

Fix: 15.1+
Fix from $1,600 2022-04-14
Wire Server HIGH 7.5
CVE-2021-41119

Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial of service attack via a crafte…

Fix: 2022-03-01+
Fix from $1,950 2022-04-13
Mattermost Server MEDIUM 6.5
CVE-2022-1337

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authentica…

Fix: 5.37.9 / 6.2.5+
Fix from $1,600 2022-04-13
Scada Server HIGH 7.5
CVE-2022-21155

A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrServic…

Fix: after 3.77
Fix from $1,950 2022-04-12
Simatic Pcs Neo HIGH 7.5
CVE-2022-27194

A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15,…

Fix: 3.1+
Fix from $1,950 2022-04-12
Simatic Cfu Diq Firmware HIGH 7.5
CVE-2022-25622

The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP…

Fix: 2.0.0+
Fix from $1,950 2022-04-12
Nokogiri HIGH 7.5
CVE-2022-24836

Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to exce…

Fix: 1.13.4 / 13.1+
Fix from $1,950 2022-04-11
Nekohtml HIGH 7.5
CVE-2022-24839

org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryErro…

Fix: 1.9.22.noko2+
Fix from $1,950 2022-04-11
Libtiff MEDIUM 6.5
CVE-2022-1210

A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a m…

No fix yet
Fix from $1,600 2022-04-03
GitLab MEDIUM 5.7
CVE-2022-0489

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature w…

Fix: 14.6.5 / 14.8.2+
Fix from $1,600 2022-04-01
Capi Release MEDIUM 5.3
CVE-2021-22100

In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or malici…

Fix: 1.122.0 / 17.1.0+
Fix from $1,600 2022-03-25
Drupal HIGH 7.5
CVE-2022-24729

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plug…

Fix: 4.18.0 / 9.2.15+
Fix from $1,950 2022-03-16
Centum Cs 3000 Firmware HIGH 8.1
CVE-2022-22145

CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 vers…

Mitigation only
Fix from $1,950 2022-03-11
Istio HIGH 7.5
CVE-2022-24726

Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a requ…

Fix: 1.11.8 / 1.12.5+
Fix from $1,950 2022-03-10
Python MEDIUM 6.5
CVE-2021-3733

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser)…

Fix: 3.6.14 / 3.7.11+
Fix from $1,600 2022-03-10
Nextcloud Server MEDIUM 6.5
CVE-2022-24741

Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uplo…

Fix: 21.0.8 / 22.2.4+
Fix from $1,600 2022-03-09
Fedora HIGH 7.5
CVE-2022-24464

.NET and Visual Studio Denial of Service Vulnerability

Fix: 16.7.26 / 16.9.18+
Fix from $1,950 2022-03-09
Regex HIGH 7.5
CVE-2022-24713EPSS 14%

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service a…

Fix: 1.5.5+
Fix from $1,950 2022-03-08
Python HIGH 7.5
CVE-2021-3737EPSS 12%

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP …

Fix: 3.6.14 / 3.7.11+
Fix from $1,950 2022-03-04
Go Ethereum HIGH 7.5
CVE-2022-23328

A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all …

No fix yet
Fix from $1,950 2022-03-04
Fscrypt MEDIUM 5.5
CVE-2022-25326

fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem …

Fix: after 0.3.2
Fix from $1,600 2022-02-25
Radare2 HIGH 7.5
CVE-2021-4021

A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary …

Fix: after 5.5.0
Fix from $1,950 2022-02-24
Fedora MEDIUM 5.5
CVE-2022-0695

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

Fix: 5.6.4+
Fix from $1,600 2022-02-24