Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Vaadin HIGH 7.5
CVE-2021-31409

Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 th…

Fix: after 8.12.4
Fix from $1,950 2021-05-06
Catalyst Sd Wan Manager HIGH 7.5
CVE-2021-1275

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to…

Fix: 20.3.3 / 20.4.1+
Fix from $1,950 2021-05-06
Ox Guard HIGH 7.5
CVE-2020-28944

OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data.

Fix: after 2.10.4
Fix from $1,950 2021-04-30
Firepower Device Manager MEDIUM 6.5
CVE-2021-1489

A vulnerability in filesystem usage management for Cisco Firepower Device Manager (FDM) Software could allow an authenticated, remote attacker to exh…

Fix: 6.4.0.12 / 6.6.4+
Fix from $1,600 2021-04-29
Ckeditor5 Engine MEDIUM 6.5
CVE-2021-21391

CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckedi…

Fix: 27.0.0+
Fix from $1,600 2021-04-29
Redis HIGH 7.5
CVE-2021-29469

Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages co…

Fix: 3.1.1+
Fix from $1,950 2021-04-23
Vaadin HIGH 7.5
CVE-2020-36320

Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attack…

Fix: 7.7.22+
Fix from $1,950 2021-04-23
Flow HIGH 7.5
CVE-2021-31405

Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and…

Fix: 2.3.3 / 4.0.3+
Fix from $1,950 2021-04-23
Junos MEDIUM 6.5
CVE-2021-0257

On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPCs (Modular Port Concentrators) where Integrated Routing and Bridging (IR…

Mitigation only
Fix from $1,600 2021-04-22
Junos MEDIUM 5.3
CVE-2021-0229

An uncontrolled resource consumption vulnerability in Message Queue Telemetry Transport (MQTT) server of Juniper Networks Junos OS allows an attacker…

Mitigation only
Fix from $1,600 2021-04-22
Junos HIGH 7.5
CVE-2021-0230

On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interfac…

Mitigation only
Fix from $1,950 2021-04-22
Junos HIGH 7.5
CVE-2021-0233

A vulnerability in Juniper Networks Junos OS ACX500 Series, ACX4000 Series, may allow an attacker to cause a Denial of Service (DoS) by sending a hig…

Mitigation only
Fix from $1,950 2021-04-22
Junos MEDIUM 5.5
CVE-2021-0238

When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executing certain CLI command may cau…

Mitigation only
Fix from $1,600 2021-04-22
Stationguard HIGH 7.5
CVE-2021-30464

OMICRON StationGuard before 1.10 allows remote attackers to cause a denial of service (connectivity outage) via crafted tcp/20499 packets to the CTRL…

Fix: 1.10+
Fix from $1,950 2021-04-20
Matrix Media Repo MEDIUM 6.5
CVE-2021-29453

matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle …

Fix: 1.2.7+
Fix from $1,600 2021-04-19
Sydent HIGH 7.5
CVE-2021-29430

Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send a…

Fix: 2.3.0+
Fix from $1,950 2021-04-15
Zxa10 C300m Firmware MEDIUM 5.3
CVE-2021-21728

A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker can consume system processing resources…

Fix: 4.5+
Fix from $1,600 2021-04-09
System Update MEDIUM 5.5
CVE-2021-21529

Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low privileges…

Fix: 1.9+
Fix from $1,600 2021-04-02
Cxf HIGH 7.5
CVE-2021-22696EPSS 7%

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F…

Fix: 3.3.10 / 3.4.3+
Fix from $1,950 2021-04-02
Jenkins HIGH 7.5
CVE-2021-28165EPSS 54%

In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS f…

Fix: 2.277.3 / 2.286+
Fix from $1,950 2021-04-01
Libzmq MEDIUM 6.5
CVE-2021-20234

An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a …

Fix: 4.3.3+
Fix from $1,600 2021-04-01
Debian Linux MEDIUM 5.5
CVE-2021-3478

There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 5.5
CVE-2021-3479

There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Is My Json Valid MEDIUM 5.3
CVE-2018-1107

It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email f…

Fix: 1.4.1 / 2.17.2+
Fix from $1,600 2021-03-30
Braces MEDIUM 5.3
CVE-2018-1109

A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression …

Fix: 2.3.1+
Fix from $1,600 2021-03-30
Privoxy HIGH 7.5
CVE-2021-20216

A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of servic…

Fix: 3.0.31+
Fix from $1,950 2021-03-25
iOS HIGH 7.5
CVE-2021-1460

A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial IS…

Fix: 1.3.2 / 1.12.0.3+
Fix from $1,950 2021-03-24
Jboss Remoting HIGH 7.5
CVE-2019-19343

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holdi…

Fix: 2.0.25 / 5.0.14+
Fix from $1,950 2021-03-23
Activemq HIGH 7.5
CVE-2021-21348EPSS 14%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23
Activemq HIGH 7.5
CVE-2021-21341EPSS 78%

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo…

Fix: 1.4.16 / 5.5+
Fix from $1,950 2021-03-23