Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Blaze HIGH 7.5
CVE-2021-21293

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are a…

Fix: 0.14.15+
Fix from $1,950 2021-02-02
Http4s HIGH 7.5
CVE-2021-21294

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have…

Fix: 0.21.17+
Fix from $1,950 2021-02-02
Docker MEDIUM 6.5
CVE-2021-21285

In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the doc…

Fix: 19.03.15 / 20.10.3+
Fix from $1,600 2021-02-02
Fedora MEDIUM 5.3
CVE-2020-28493

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its u…

Fix: 2.11.3+
Fix from $1,600 2021-02-01
Ckeditor5 MEDIUM 6.5
CVE-2021-21254

CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm…

Fix: 25.0.0+
Fix from $1,600 2021-01-29
4cct Ea6 334126bf Firmware HIGH 7.5
CVE-2021-25909

ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition…

Mitigation only
Fix from $1,950 2021-01-29
Moodle MEDIUM 5.3
CVE-2021-20185

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which co…

Fix: 3.5.16 / 3.8.7+
Fix from $1,600 2021-01-28
Serverprotect MEDIUM 5.5
CVE-2021-25224

A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a de…

Patch available
Fix from $1,600 2021-01-27
Serverprotect MEDIUM 5.5
CVE-2021-25225

A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a de…

Patch available
Fix from $1,600 2021-01-27
Serverprotect MEDIUM 5.5
CVE-2021-25226

A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a de…

Patch available
Fix from $1,600 2021-01-27
Tendermint MEDIUM 6.5
CVE-2021-21271

Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - written in any programming langua…

Fix: after 0.34.2
Fix from $1,600 2021-01-26
Opc Ua Tunneller HIGH 7.5
CVE-2020-27295

The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA T…

Fix: 6.3.0.8233+
Fix from $1,950 2021-01-26
Nextcloud Server MEDIUM 6.5
CVE-2020-8293

A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and…

Fix: 18.0.11 / 19.0.5+
Fix from $1,600 2021-01-26
Nextcloud Server HIGH 7.5
CVE-2020-8295

A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.

Fix: 20.0.0+
Fix from $1,950 2021-01-26
Mq Internet Pass Thru HIGH 7.5
CVE-2020-4766

IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consum…

Patch available
Fix from $1,950 2021-01-22
Elastic Services Controller HIGH 7.5
CVE-2021-1312

A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause…

Fix: after 5.3.0.94
Fix from $1,950 2021-01-20
Junos MEDIUM 6.5
CVE-2021-0215

On Juniper Networks Junos EX series, QFX Series, MX Series and SRX branch series devices, a memory leak occurs every time the 802.1X authenticator po…

No fix yet
Fix from $1,600 2021-01-15
Junos HIGH 7.5
CVE-2021-0202

On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB)…

Mitigation only
Fix from $1,950 2021-01-15
GitLab HIGH 7.5
CVE-2021-22166

An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method

Fix: 13.7.2+
Fix from $1,950 2021-01-15
GitLab MEDIUM 6.5
CVE-2021-22168

A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8.

Fix: 13.5.6 / 13.6.4+
Fix from $1,600 2021-01-15
Jquery Validation HIGH 7.5
CVE-2021-21252

The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-valid…

Fix: 1.19.3+
Fix from $1,950 2021-01-13
Engine.io HIGH 7.5
CVE-2020-36048

Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

Fix: 4.0.0+
Fix from $1,950 2021-01-08
Cairosvg MEDIUM 5.5
CVE-2021-21236

CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression den…

Fix: 2.5.1+
Fix from $1,600 2021-01-06
Kamadak Exif MEDIUM 6.5
CVE-2021-21235

kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop in parsing crafted PNG files. …

Patch available
Fix from $1,600 2021-01-06
Emc Unity Operating Environment MEDIUM 6.5
CVE-2020-29490

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A r…

Fix: 5.0.4.0.5.012+
Fix from $1,600 2021-01-05
Trust Dns Server HIGH 7.5
CVE-2020-35857

An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption.

Fix: 0.18.1+
Fix from $1,950 2020-12-31
Image MEDIUM 5.5
CVE-2020-35916

An issue was discovered in the image crate before 0.23.12 for Rust. A Mutable reference has immutable provenance. (In the case of LLVM, the IR may be…

Fix: 0.23.12+
Fix from $1,600 2020-12-31
Date And Time HIGH 7.5
CVE-2020-26289

date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsin…

Fix: 0.14.2+
Fix from $1,950 2020-12-28
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2020-27722

In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-con…

Fix: 13.1.3.5 / 14.1.3.1+
Fix from $1,600 2020-12-24
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2020-27724

In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on sy…

Fix: 13.1.3.5 / 14.1.3.1+
Fix from $1,600 2020-12-24