Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Schema Inspector HIGH 7.5
CVE-2021-21267

Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address va…

Fix: 2.0.0+
Fix from $1,950 2021-03-19
Fedora HIGH 7.5
CVE-2021-28089

Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

Fix: 0.3.5.14 / 0.4.4.8+
Fix from $1,950 2021-03-19
Openshift Container Platform HIGH 7.5
CVE-2020-27827

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle speci…

Fix: 1.0.8 / 2.6.9+
Fix from $1,950 2021-03-18
Debian Linux MEDIUM 6.5
CVE-2021-21375

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.10
Fix from $1,600 2021-03-10
Gs116e Firmware MEDIUM 6.5
CVE-2020-35233

The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device re…

Mitigation only
Fix from $1,600 2021-03-10
Linux Kernel MEDIUM 5.5
CVE-2021-20265

A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw …

Fix: after 7.7.1
Fix from $1,600 2021-03-10
Besu MEDIUM 6.5
CVE-2021-21369

Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vu…

Fix: 1.5.1+
Fix from $1,600 2021-03-09
Node.js HIGH 7.5
CVE-2021-22883EPSS 74%

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownP…

Fix: 9.2.6.0 / 10.24.0+
Fix from $1,950 2021-03-03
Apex Central MEDIUM 5.5
CVE-2021-25252

Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to de…

Patch available
Fix from $1,600 2021-03-03
Nifi MEDIUM 5.3
CVE-2020-27223EPSS 78%

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers …

Fix: 9.4.36+
Fix from $1,600 2021-02-26
Fedora MEDIUM 6.5
CVE-2021-21274

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…

Fix: 1.25.0+
Fix from $1,600 2021-02-26
Pm554 Firmware HIGH 7.5
CVE-2020-24686

The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing rem…

Mitigation only
Fix from $1,950 2021-02-26
Vapor MEDIUM 5.3
CVE-2021-21328

Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their V…

Fix: 4.40.1+
Fix from $1,600 2021-02-26
Jboss Fuse HIGH 7.5
CVE-2020-27782

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings…

Mitigation only
Fix from $1,950 2021-02-23
Unifi Protect Controller HIGH 7.5
CVE-2021-22882

UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect control…

Fix: 1.17.1+
Fix from $1,950 2021-02-23
Aqt1000 Firmware HIGH 7.5
CVE-2020-11270

Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM parameter IE in Sna…

No fix yet
Fix from $1,950 2021-02-22
Scrapbox Parser HIGH 7.5
CVE-2021-27405

A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js.

Fix: 6.0.3+
Fix from $1,950 2021-02-19
Three HIGH 7.5
CVE-2020-28496

This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require('three') function build_blan…

Fix: 0.125.0+
Fix from $1,950 2021-02-18
Staros HIGH 7.5
CVE-2021-1378

A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device t…

Fix: after 21.19.10
Fix from $1,950 2021-02-17
Ethernet Network Adapter E810 Firmware MEDIUM 5.5
CVE-2020-24504

Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to po…

Fix: 1.0.4+
Fix from $1,600 2021-02-17
Gerrit HIGH 7.5
CVE-2021-22553

Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the …

Fix: 2.15.22 / 2.16.26+
Fix from $1,950 2021-02-17
Uap Core MEDIUM 5.3
CVE-2021-21317

uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In uap-core before version 0.11.0…

Fix: 0.11.0+
Fix from $1,600 2021-02-16
Hive HIGH 7.5
CVE-2020-13949EPSS 7%

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leadin…

Fix: 4.0.0+
Fix from $1,950 2021-02-12
Big Ip Application Security Manager HIGH 7.5
CVE-2021-22985

On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malici…

Fix: 11.6.5.2 / 12.1.5.3+
Fix from $1,950 2021-02-12
Rails HIGH 7.5
CVE-2021-22880

The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. C…

Fix: 5.2.4.5 / 6.0.3.5+
Fix from $1,950 2021-02-11
Debian Linux HIGH 7.5
CVE-2020-35498EPSS 8%

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a special…

Fix: 2.5.12 / 2.6.10+
Fix from $1,950 2021-02-11
Spectrum Protect Plus HIGH 7.5
CVE-2020-5023

IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to exc…

Fix: after 10.1.7
Fix from $1,950 2021-02-10
Marked HIGH 7.5
CVE-2021-21306

Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regul…

Fix: 2.0.0+
Fix from $1,950 2021-02-08
Httplib2 HIGH 7.5
CVE-2021-21240

httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of …

Fix: 0.19.0+
Fix from $1,950 2021-02-08
Managed Services Accelerator MEDIUM 6.5
CVE-2021-1266

A vulnerability in the REST API of Cisco Managed Services Accelerator (MSX) could allow an authenticated, remote attacker to cause a denial of servic…

Fix: 3.10.0+
Fix from $1,600 2021-02-04