Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Micronaut MEDIUM 5.3
CVE-2022-21700

Micronaut is a JVM-based, full stack Java framework designed for building JVM web applications with support for Java, Kotlin and the Groovy language.…

Fix: 3.2.7+
Fix from $1,600 2022-01-18
Onionshare HIGH 7.5
CVE-2022-21689

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In …

Fix: 2.5+
Fix from $1,950 2022-01-18
Mattermost MEDIUM 5.7
CVE-2021-37865

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows auth…

Fix: after 6.2.0
Fix from $1,600 2022-01-18
GitLab MEDIUM 6.5
CVE-2021-39942

A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions starting from 14.4 before 14.…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2022-01-18
Fedora HIGH 7.5
CVE-2022-21680

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against som…

Fix: 4.0.10+
Fix from $1,950 2022-01-14
Fedora HIGH 7.5
CVE-2022-21681

Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking …

Fix: 4.0.10+
Fix from $1,950 2022-01-14
Ar8035 Firmware HIGH 7.5
CVE-2021-30301

Possible denial of service due to out of memory while processing RRC and NAS OTA message in Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mo…

Mitigation only
Fix from $1,950 2022-01-13
Markdown It MEDIUM 5.3
CVE-2022-21670

markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parse…

Fix: after 12.3.1
Fix from $1,600 2022-01-10
Mediawiki HIGH 7.5
CVE-2021-46149

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be…

Fix: 1.35.5 / 1.36.3+
Fix from $1,950 2022-01-10
Emui HIGH 7.5
CVE-2021-40011

There is an uncontrolled resource consumption vulnerability in the display module. Successful exploitation of this vulnerability may affect integrity.

No fix yet
Fix from $1,950 2022-01-10
500 Series Firmware MEDIUM 6.5
CVE-2020-9059

Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to batt…

Mitigation only
Fix from $1,600 2022-01-10
500 Series Firmware MEDIUM 6.5
CVE-2020-9060

Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 versio…

Mitigation only
Fix from $1,600 2022-01-10
Jawn HIGH 7.5
CVE-2022-21653

Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFacade` who don't override `obj…

Fix: 1.3.2+
Fix from $1,950 2022-01-05
Stars Rating HIGH 7.5
CVE-2021-24893

The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Servi…

Fix: 3.5.1+
Fix from $1,950 2022-01-03
Pq8009 Firmware MEDIUM 6.5
CVE-2021-30348

Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,…

Mitigation only
Fix from $1,600 2022-01-03
Go HIGH 7.5
CVE-2021-44716

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 request…

Fix: 1.16.12 / 1.17.5+
Fix from $1,950 2022-01-01
Nltk HIGH 7.5
CVE-2021-43854

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Lan…

Fix: 3.6.5+
Fix from $1,950 2021-12-23
Jsx Slack HIGH 7.5
CVE-2021-43843

jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch for CVE-2021-43838 in jsx-sla…

Fix: 4.5.2+
Fix from $1,950 2021-12-20
Jsx Slack HIGH 7.5
CVE-2021-43838

jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users are vulnerable to a regular …

Fix: 4.5.2+
Fix from $1,950 2021-12-17
GitLab MEDIUM 6.5
CVE-2021-39938

A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
GitLab MEDIUM 6.5
CVE-2021-39939

An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.3.6, all versions starting fr…

Fix: 14.3.6 / 14.4.4+
Fix from $1,600 2021-12-13
Log4j CRITICAL 10.0
CVE-2021-44228 KEVEPSS 100%

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…

Fix: 2.1.0 / 2.3.1+
Fix from $2,300 2021-12-10
Fortiweb HIGH 7.5
CVE-2021-41014

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the htt…

Fix: after 6.3.15
Fix from $1,950 2021-12-08
Harmonyos HIGH 7.5
CVE-2021-37061

There is a Uncontrolled Resource Consumption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Screen proj…

Fix: 2.0+
Fix from $1,950 2021-12-07
Unifi Switch Firmware MEDIUM 6.5
CVE-2021-44527

A vulnerability found in UniFi Switch firmware Version 5.43.35 and earlier allows a malicious actor who has already gained access to the network to p…

Fix: 5.76.6+
Fix from $1,600 2021-12-07
Application Delivery Controller Firmware HIGH 7.5
CVE-2021-22955

A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or …

Fix: 11.1-65.23 / 12.1-63.22+
Fix from $1,950 2021-12-07
Application Delivery Controller Firmware HIGH 7.5
CVE-2021-22956

An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with acc…

Fix: 10.2.9c / 11.1-65.23+
Fix from $1,950 2021-12-07
Fedora HIGH 7.5
CVE-2021-44686

calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in eb…

Fix: 5.32.0+
Fix from $1,950 2021-12-07
Melsec Iq R R00 Cpu Firmware HIGH 7.5
CVE-2021-20609

Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, M…

Fix: after 57
Fix from $1,950 2021-12-01
Topease MEDIUM 6.5
CVE-2021-42120

Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on all object attrib…

Fix: after 7.1.27
Fix from $1,600 2021-11-30