Vulnerability index

Browse CVEs

3,116 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2023-51301 A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive am… Hotel Booking System No fix yet Fix from $1,9502025-02-19 HIGH 7.5 CVE-2023-51293 A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Event Booking Calendar v4.0 allows attackers to send an exce… Event Booking Calendar No fix yet Fix from $1,9502025-02-19 MEDIUM 6.8 CVE-2024-57782 An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service. No fix yet Fix from $1,6002025-02-13 HIGH 7.5 CVE-2023-34397 Mercedes Benz head-unit NTG 6 contains functions to import or export profile settings over USB. During parsing you can trigger that the service will … Headunit Ntg6 Mercedes Benz User Experience after 2021 Fix from $1,9502025-02-13 MEDIUM 6.2 CVE-2025-0426 A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTT… Mitigation only Fix from $1,6002025-02-13 HIGH 7.5 CVE-2024-56940 An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads. Learndash Mitigation only Fix from $1,9502025-02-12 HIGH 7.5 CVE-2024-46923 An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service at amdgpu_c… Exynos 2200 Firmware Mitigation only Fix from $1,9502025-02-12 HIGH 8.2 CVE-2025-25205 Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication by… Audiobookshelf 2.19.1+ Fix from $1,9502025-02-12 HIGH 7.5 CVE-2025-21351 Windows Active Directory Domain Services API Denial of Service Vulnerability Windows 10 1607 10.0.14393.7785 / 10.0.17763.6893+ Fix from $1,9502025-02-11 MEDIUM 6.5 CVE-2025-21352 Internet Connection Sharing (ICS) Denial of Service Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,6002025-02-11 HIGH 7.5 CVE-2025-21181 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,9502025-02-11 MEDIUM 5.3 CVE-2024-23814 The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory resources when receiving speciall… Mitigation only Fix from $1,6002025-02-11 MEDIUM 5.5 CVE-2025-25193 Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe read… Netty 4.1.118+ Fix from $1,6002025-02-10 MEDIUM 6.5 CVE-2024-54658 The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, vi… Safari 1.1 / 10.4+ Fix from $1,6002025-02-10 MEDIUM 6.5 CVE-2025-25186 Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4… Patch available Fix from $1,6002025-02-10 MEDIUM 5.5 CVE-2024-57672 An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topologylnstance module, Routing mo… Floodlight Mitigation only Fix from $1,6002025-02-06 MEDIUM 5.5 CVE-2024-57673 An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Linkdiscovery module Floodlight No fix yet Fix from $1,6002025-02-06 HIGH 7.5 CVE-2024-45626 Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can resu… James Server 3.7.6 / 3.8.2+ Fix from $1,9502025-02-06 HIGH 7.5 CVE-2024-57079 A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a craft… Mitigation only Fix from $1,9502025-02-05 HIGH 7.5 CVE-2024-57081 A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a … Mitigation only Fix from $1,9502025-02-05 MEDIUM 6.5 CVE-2024-57082 A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying … Mitigation only Fix from $1,6002025-02-05 HIGH 7.5 CVE-2024-57085 A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a c… Mitigation only Fix from $1,9502025-02-05 HIGH 7.5 CVE-2024-57074 A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted paylo… Mitigation only Fix from $1,9502025-02-05 HIGH 7.5 CVE-2024-57075 A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted pa… Mitigation only Fix from $1,9502025-02-05 HIGH 7.5 CVE-2024-57076 A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS) via supplying a crafted pay… Mitigation only Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-21087 When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclosed traffic can cause an incr… Big Ip Access Policy Manager 16.1.6 / 17.1.2+ Fix from $1,9502025-02-05 HIGH 7.5 CVE-2025-20058 When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. No… Big Ip Access Policy Manager 16.1.6 / 17.1.2+ Fix from $1,9502025-02-05 MEDIUM 6.5 CVE-2024-53851 Discourse is an open source platform for community discussion. In affected versions the endpoint for generating inline oneboxes for URLs wasn't enfor… Discourse 3.3.3 / 3.4.0+ Fix from $1,6002025-02-04 HIGH 7.5 CVE-2024-56921 An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handli… Open5gs Patch available Fix from $1,9502025-02-03 HIGH 7.5 CVE-2024-57519 An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file. Open5gs Patch available Fix from $1,9502025-01-28