Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Fastify Static HIGH 8.8
CVE-2021-22964

A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect Mozilla Firefox users to arb…

Fix: 4.4.1+
Fix from $1,950 2021-10-14
Ruggedcom Rox Mx5000 Firmware HIGH 7.5
CVE-2021-41546

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.14.1), RUGGEDCOM ROX RX1400 (All versions < V2.14.1), RUGGEDCOM ROX RX…

Fix: 2.14.1+
Fix from $1,950 2021-10-12
R12ccpu V Firmware MEDIUM 5.9
CVE-2021-20600

Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versions "16" and prior allows a r…

Fix: after 16
Fix from $1,600 2021-10-08
Zulip MEDIUM 6.5
CVE-2021-41115

Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that au…

Fix: 4.7+
Fix from $1,600 2021-10-07
Dynamicpagelist3 HIGH 7.5
CVE-2021-41118

The DynamicPageList3 extension is a reporting tool for MediaWiki, listing category members and intersections with various formats and details. In aff…

Fix: 3.3.6+
Fix from $1,950 2021-10-04
GitLab MEDIUM 5.5
CVE-2021-39877

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a special…

Fix: 14.1.7 / 14.2.5+
Fix from $1,600 2021-10-04
Jsoneditor HIGH 7.5
CVE-2021-3822

jsoneditor is vulnerable to Inefficient Regular Expression Complexity

Fix: 9.5.6+
Fix from $1,950 2021-09-27
Cloud Foundation HIGH 7.5
CVE-2021-22010

The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server ma…

Fix: 5.0+
Fix from $1,950 2021-09-23
Apprise HIGH 7.5
CVE-2021-39229

Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. In affec…

Fix: 0.9.5.1+
Fix from $1,950 2021-09-20
Flask Restx HIGH 7.5
CVE-2021-32838

Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular…

Fix: 0.5.1+
Fix from $1,950 2021-09-20
Sqlparse HIGH 7.5
CVE-2021-32839

sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expression Denial of Service in sq…

Fix: 0.4.2+
Fix from $1,950 2021-09-20
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23042

On BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, and 12.1.x before 12.1.6, when an HTTP pr…

Fix: 12.1.6 / 13.1.4+
Fix from $1,950 2021-09-14
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2021-23047

On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM perform…

Fix: 13.1.4 / 14.1.4.3+
Fix from $1,600 2021-09-14
Big Ip Access Policy Manager HIGH 7.5
CVE-2021-23049

On BIG-IP version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3, when the iRules RESOLVER::summarize command is used on a virtual server, undisclos…

Fix: 15.1.3 / 16.0.1.2+
Fix from $1,950 2021-09-14
Big Ip Advanced Web Application Firewall MEDIUM 5.3
CVE-2021-23053

On version 15.1.x before 15.1.3, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6, when the brute force protection feature of BIG-IP Advanced WAF o…

Fix: 13.1.3.6 / 14.1.3.1+
Fix from $1,600 2021-09-14
Iportalis Control Portal HIGH 7.5
CVE-2020-9000

An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This incr…

Mitigation only
Fix from $1,950 2021-09-01
Axios HIGH 7.5
CVE-2021-3749EPSS 9%

axios is vulnerable to Inefficient Regular Expression Complexity

Fix: 1.0 / 21.7.0.0.0+
Fix from $1,950 2021-08-31
Rocket.chat MEDIUM 6.5
CVE-2021-32832

Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and …

Fix: 3.11.3 / 3.12.2+
Fix from $1,600 2021-08-30
Passport Saml HIGH 7.5
CVE-2021-39171

Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3.1.0, a malicious SAML payloa…

Fix: 3.1.0+
Fix from $1,950 2021-08-27
Roller HIGH 7.5
CVE-2021-33580

User controlled `request.getHeader("Referer")`, `request.getRequestURL()` and `request.getQueryString()` are used to build and run a regex expression…

Fix: 6.0.2+
Fix from $1,950 2021-08-18
Automation License Manager HIGH 7.5
CVE-2021-25659

A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 Update 2). …

Fix: 6.0.9+
Fix from $1,950 2021-08-10
Linux Kernel MEDIUM 5.5
CVE-2021-3679

A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffe…

Fix: 5.14+
Fix from $1,600 2021-08-05
Fortiauthenticator HIGH 7.5
CVE-2021-22124

An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4,…

Fix: 3.0.7 / 3.1.5+
Fix from $1,950 2021-08-04
Powerscale Onefs MEDIUM 5.3
CVE-2021-21565

Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error condition that may be trigger…

Fix: after 9.1.0.3
Fix from $1,600 2021-08-03
Pcoip Client MEDIUM 5.5
CVE-2021-25701

The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety of IOCTLs…

Fix: 21.07.0+
Fix from $1,600 2021-07-21
Routeros MEDIUM 6.5
CVE-2020-20221

Mikrotik RouterOs before 6.44.6 (long-term tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/cerm process. An au…

Fix: 6.44.6+
Fix from $1,600 2021-07-21
Openproject MEDIUM 6.5
CVE-2021-32763

OpenProject is open-source, web-based project management software. In versions prior to 11.3.3, the `MessagesController` class of OpenProject has a `…

Fix: 11.3.3+
Fix from $1,600 2021-07-20
Routeros MEDIUM 6.5
CVE-2020-20248

Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can c…

No fix yet
Fix from $1,600 2021-07-19
Routeros MEDIUM 6.5
CVE-2020-20230

Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the sshd process. An authenticated remote attacker can caus…

Fix: 6.47+
Fix from $1,600 2021-07-19
Sheetjs MEDIUM 5.5
CVE-2021-32012

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishan…

Fix: 21.2.4+
Fix from $1,600 2021-07-19