Vulnerability index

Browse CVEs

3,130 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
Handlebars HIGH 7.5
CVE-2019-20922

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop …

Fix: 4.4.5+
Fix from $1,950 2020-09-30
Pexip Infinity HIGH 7.5
CVE-2018-10432

Pexip Infinity before 18 allows Remote Denial of Service (TLS handshakes in RTMP).

Fix: 18+
Fix from $1,950 2020-09-25
Pexip Infinity HIGH 7.5
CVE-2018-10585

Pexip Infinity before 18 allows remote Denial of Service (XML parsing).

Fix: 18+
Fix from $1,950 2020-09-25
Wireless Lan Controller HIGH 8.6
CVE-2020-3560

A vulnerability in Cisco Aironet Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on an affecte…

Fix: 8.5.161.0 / 8.8.130.0+
Fix from $1,950 2020-09-24
Ios Xe HIGH 8.6
CVE-2020-3510

A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, …

Mitigation only
Fix from $1,950 2020-09-24
Ios Xe HIGH 7.4
CVE-2020-3512

A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco IOS Software and Cisco IOS XE Software could allow…

Mitigation only
Fix from $1,950 2020-09-24
Ios Xe HIGH 8.6
CVE-2020-3527

A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The…

Fix: 16.9.5 / 16.12.3+
Fix from $1,950 2020-09-24
Wireless Lan Controller HIGH 8.6
CVE-2020-3559

A vulnerability in Cisco Aironet Access Point (AP) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. Th…

Fix: 8.10.112.0 / 10.1.1.0+
Fix from $1,950 2020-09-24
iOS HIGH 7.5
CVE-2020-3479

A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address famil…

Mitigation only
Fix from $1,950 2020-09-24
Ios Xe MEDIUM 6.5
CVE-2020-3487

Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Ca…

Mitigation only
Fix from $1,600 2020-09-24
Ios Xe HIGH 7.4
CVE-2020-3508

A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers w…

Mitigation only
Fix from $1,950 2020-09-24
Ios Xe MEDIUM 6.5
CVE-2020-3428

A vulnerability in the WLAN Local Profiling feature of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an un…

Mitigation only
Fix from $1,600 2020-09-24
iOS HIGH 8.6
CVE-2020-3408

A vulnerability in the Split DNS feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an …

Mitigation only
Fix from $1,950 2020-09-24
iOS HIGH 7.4
CVE-2020-3409

A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an…

Mitigation only
Fix from $1,950 2020-09-24
Ios Xe HIGH 8.6
CVE-2020-3414

A vulnerability in the packet processing of Cisco IOS XE Software for Cisco 4461 Integrated Services Routers could allow an unauthenticated, remote a…

Mitigation only
Fix from $1,950 2020-09-24
Ios Xr HIGH 8.6
CVE-2020-3569 KEV

Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, r…

Fix: 6.5.2+
Fix from $1,950 2020-09-23
Json Bigint HIGH 7.5
CVE-2020-8237

Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.

Fix: 1.0.0+
Fix from $1,950 2020-09-18
Application Delivery Controller Firmware HIGH 7.5
CVE-2020-8246

Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.18…

Fix: 10.2.7b / 11.0.3f+
Fix from $1,950 2020-09-18
Node.js HIGH 7.5
CVE-2020-8251EPSS 9%

Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to acce…

Fix: 14.11.0+
Fix from $1,950 2020-09-18
Ua Parser Js HIGH 7.5
CVE-2020-7733

The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Table…

Fix: 0.7.22+
Fix from $1,950 2020-09-16
Fedora HIGH 7.5
CVE-2020-15166

In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, a…

Fix: 4.3.3+
Fix from $1,950 2020-09-11
Bcoin HIGH 7.5
CVE-2018-17145

Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messa…

Fix: 0.16.2 / 1.0.2+
Fix from $1,950 2020-09-10
Pan Os MEDIUM 5.3
CVE-2020-2039EPSS 46%

An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files th…

Fix: 8.1.16 / 9.0.10+
Fix from $1,600 2020-09-09
Jboss Enterprise Application Platform HIGH 7.5
CVE-2020-14384

A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable t…

Fix: 7.5.31.final-redhat-3+
Fix from $1,950 2020-09-09
Metasploit HIGH 7.5
CVE-2019-5645EPSS 42%

By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expressi…

Fix: after 5.0.27
Fix from $1,950 2020-09-01
Ios Xr HIGH 8.6
CVE-2020-3566 KEV

A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote att…

Mitigation only
Fix from $1,950 2020-08-29
8000p Ip Camera Firmware MEDIUM 6.5
CVE-2020-3505

A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker …

Mitigation only
Fix from $1,600 2020-08-26
Opc HIGH 7.5
CVE-2020-14522

Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to uncontrolled resource c…

Fix: 4.47.0+
Fix from $1,950 2020-08-25
Cloud Foundation MEDIUM 5.3
CVE-2020-3976

VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated th…

Fix: 3.10 / 4.0.1+
Fix from $1,600 2020-08-21
Acrobat Dc MEDIUM 5.5
CVE-2020-9702

Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have a stack…

Fix: after 20.009.20074
Fix from $1,600 2020-08-19