Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Apex One HIGH 7.5
CVE-2022-24678

An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-F…

Patch available
Fix from $1,950 2022-02-24
Nx Os HIGH 7.5
CVE-2022-20624EPSS 12%

A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to caus…

Mitigation only
Fix from $1,950 2022-02-23
Fedora MEDIUM 5.5
CVE-2022-0476

Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

Fix: 5.6.4+
Fix from $1,600 2022-02-23
Enterprise Linux MEDIUM 5.5
CVE-2021-4115

There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threa…

Patch available
Fix from $1,600 2022-02-21
Vscode Xml CRITICAL 9.1
CVE-2022-0671

A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.

Fix: 0.19.0+
Fix from $2,300 2022-02-18
Client Golang HIGH 7.5
CVE-2022-21698EPSS 6%

client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTT…

Fix: 1.11.1+
Fix from $1,950 2022-02-15
Meetings MEDIUM 6.5
CVE-2022-22780

The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions: Android before version 5.8.…

Fix: 5.6.3 / 5.7.3+
Fix from $1,600 2022-02-09
Netweaver Abap HIGH 7.5
CVE-2022-22543

SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87,…

Mitigation only
Fix from $1,950 2022-02-09
Iscsi San HIGH 7.5
CVE-2007-20001

A flaw was found in StarWind iSCSI target. An attacker could script standard iSCSI Initiator operation(s) to exhaust the StarWind service socket, whi…

Fix: 3.5+
Fix from $1,950 2022-02-06
Iscsi San CRITICAL 9.8
CVE-2013-20004

A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An att…

Fix: 6.0+
Fix from $2,300 2022-02-06
Tensorflow HIGH 7.5
CVE-2022-23591

Tensorflow is an Open Source Machine Learning Framework. The `GraphDef` format in TensorFlow does not allow self recursive functions. The runtime ass…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23580

Tensorflow is an Open Source Machine Learning Framework. During shape inference, TensorFlow can allocate a large vector based on a value from a tenso…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2022-22724

A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP) and 502 (Modbus), when send…

Patch available
Fix from $1,950 2022-02-04
Jenkins HIGH 7.5
CVE-2021-43859EPSS 8%

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 1…

Fix: 1.4.19 / 2.319.3+
Fix from $1,950 2022-02-01
MariaDB MEDIUM 5.5
CVE-2021-46668

MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource …

Fix: 10.2.43 / 10.3.34+
Fix from $1,600 2022-02-01
Rlc 410w Firmware HIGH 7.5
CVE-2021-40406

A denial of service vulnerability exists in the cgiserver.cgi session creation functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-cra…

No fix yet
Fix from $1,950 2022-01-28
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-23015

On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server wit…

Fix: 14.1.4.4 / 15.1.4.1+
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-23023

On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all version…

Fix: after 16.1.2
Fix from $1,600 2022-01-25
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2022-23024

On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application laye…

Fix: after 15.1.4
Fix from $1,950 2022-01-25
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2022-23030

On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) use…

Fix: after 16.1.1
Fix from $1,600 2022-01-25
Graphql Go MEDIUM 6.5
CVE-2022-21708

graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability that is possible due to a bug…

Fix: 1.3.0+
Fix from $1,600 2022-01-21
Agilia Partner Maintenance Software HIGH 7.5
CVE-2021-23236

Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a …

Fix: 3.0+
Fix from $1,950 2022-01-21
Debian Linux MEDIUM 5.3
CVE-2022-21360

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21366

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21340EPSS 8%

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21293EPSS 8%

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21299

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux MEDIUM 5.3
CVE-2022-21277

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are af…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Junos MEDIUM 6.5
CVE-2022-22155

An Uncontrolled Resource Consumption vulnerability in the handling of IPv6 neighbor state change events in Juniper Networks Junos OS allows an adjace…

Mitigation only
Fix from $1,600 2022-01-19
Junos HIGH 7.5
CVE-2022-22161

An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated network based attacker to cau…

Fix: after 18.2
Fix from $1,950 2022-01-19