Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Sheetjs MEDIUM 5.5
CVE-2021-32013

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishan…

Fix: 21.2.4+
Fix from $1,600 2021-07-19
Sheetjs MEDIUM 5.5
CVE-2021-32014

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandle…

Fix: 21.2.4+
Fix from $1,600 2021-07-19
Junos Os Evolved MEDIUM 6.5
CVE-2021-0292

An Uncontrolled Resource Consumption vulnerability in the ARP daemon (arpd) and Network Discovery Protocol (ndp) process of Juniper Networks Junos OS…

Mitigation only
Fix from $1,600 2021-07-15
Junos HIGH 7.5
CVE-2021-0285

An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sendi…

Mitigation only
Fix from $1,950 2021-07-15
Is Email HIGH 7.5
CVE-2021-36716

A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to p…

Fix: 1.0.1+
Fix from $1,950 2021-07-14
Routeros MEDIUM 6.5
CVE-2020-20217

Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/route process. An authen…

Fix: 6.47+
Fix from $1,600 2021-07-08
Addressable HIGH 7.5
CVE-2021-32740

Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption …

Fix: 2.8.0+
Fix from $1,950 2021-07-06
Spring Security HIGH 7.5
CVE-2021-22119EPSS 6%

Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-S…

Fix: 5.2.11 / 5.3.10+
Fix from $1,950 2021-06-29
Tor HIGH 7.5
CVE-2021-34549

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an atta…

Fix: 0.3.5.15 / 0.4.4.9+
Fix from $1,950 2021-06-29
Urllib3 HIGH 7.5
CVE-2021-33503

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority reg…

Fix: 1.26.5+
Fix from $1,950 2021-06-29
Globalnewfiles MEDIUM 6.5
CVE-2021-32722

GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an uncontrolled resource consumpt…

Patch available
Fix from $1,600 2021-06-28
Prism MEDIUM 6.5
CVE-2021-32723

Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is us…

Fix: 1.24.0 / 21.1.4+
Fix from $1,600 2021-06-28
Wings MEDIUM 6.5
CVE-2021-32699

Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vu…

Fix: 1.4.4+
Fix from $1,600 2021-06-22
Mgate Mb3180 Firmware HIGH 7.5
CVE-2021-33824

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which c…

No fix yet
Fix from $1,950 2021-06-18
Camera G3 Flex Firmware HIGH 7.5
CVE-2021-33818

An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, …

No fix yet
Fix from $1,950 2021-06-18
4gee Router Hh70vb Firmware HIGH 7.5
CVE-2021-33822

An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E1_02.00_22. Attackers can use slowhttptest tool to send incomplete HTTP request, which co…

No fix yet
Fix from $1,950 2021-06-18
Gateway MEDIUM 6.5
CVE-2020-8299

Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WA…

Fix: 10.2.9a / 11.1.2c+
Fix from $1,600 2021-06-16
Cxf HIGH 7.5
CVE-2021-30468EPSS 7%

A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thr…

Fix: 3.3.11 / 3.4.4+
Fix from $1,950 2021-06-16
Rails HIGH 7.5
CVE-2021-22902

The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of …

Fix: 6.0.3.7 / 6.1.0.2+
Fix from $1,950 2021-06-11
Rails HIGH 7.5
CVE-2021-22904

The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication l…

Fix: 5.2.4.6 / 5.2.6+
Fix from $1,950 2021-06-11
End To End Encryption MEDIUM 6.5
CVE-2021-22906

Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated user…

Fix: 1.5.3 / 1.6.3+
Fix from $1,600 2021-06-11
GitLab MEDIUM 6.5
CVE-2021-22181

A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship an…

Fix: 13.10.5 / 13.11.5+
Fix from $1,600 2021-06-11
R00cpu Firmware HIGH 7.5
CVE-2021-20591

Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN…

Mitigation only
Fix from $1,950 2021-06-11
Jhl6240 Thunderbolt 3 Firmware MEDIUM 5.5
CVE-2020-12291

Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of servic…

Fix: 21 / 22+
Fix from $1,600 2021-06-09
Dsl5320 Thunderbolt 2 Firmware MEDIUM 5.5
CVE-2020-12296

Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of servic…

Fix: 21 / 22+
Fix from $1,600 2021-06-09
GitLab MEDIUM 6.5
CVE-2021-22216

A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resourc…

Fix: 13.10.5 / 13.11.5+
Fix from $1,600 2021-06-08
Simatic Rf166c Firmware HIGH 7.5
CVE-2021-31340

A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2), SIMATIC …

Fix: 1.3.2 / 2.0+
Fix from $1,950 2021-06-08
Openexr MEDIUM 5.5
CVE-2021-26945

An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an appl…

Fix: 3.0.1+
Fix from $1,600 2021-06-08
Rabbitmq HIGH 7.5
CVE-2021-22116

RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection e…

Fix: 3.8.16+
Fix from $1,950 2021-06-08
Fedora MEDIUM 5.5
CVE-2021-23215

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this …

Fix: 3.0.1+
Fix from $1,600 2021-06-08