Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 6.5 CVE-2024-52520 Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downlo… Nextcloud Server 27.1.11.8 / 28.0.10+ Fix from $1,6002024-11-15 HIGH 8.6 CVE-2023-20125 A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacker to exhaust system resources… Mitigation only Fix from $1,9502024-11-15 HIGH 7.5 CVE-2024-48989 A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of servic… Mitigation only Fix from $1,9502024-11-13 HIGH 7.5 CVE-2024-9409 CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss… Powerlogic Pm5341 Firmware 2.4.0 / 2.7.0+ Fix from $1,9502024-11-13 MEDIUM 5.5 CVE-2024-47535 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients… Netty 4.1.115+ Fix from $1,6002024-11-12 HIGH 7.5 CVE-2024-46891 A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of … Sinec Ins after 1.0 Fix from $1,9502024-11-12 HIGH 8.7 CVE-2024-10314 In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported … Mitigation only Fix from $1,9502024-11-11 HIGH 8.7 CVE-2024-10344 In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol … Mitigation only Fix from $1,9502024-11-11 HIGH 8.7 CVE-2024-10345 In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karo… Mitigation only Fix from $1,9502024-11-11 MEDIUM 5.3 CVE-2024-38826 Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be used to run a denial of service … Mitigation only Fix from $1,6002024-11-11 MEDIUM 5.5 CVE-2024-51513 Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consu… Harmonyos No fix yet Fix from $1,6002024-11-05 HIGH 7.5 CVE-2024-10599 A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the … Office Anywhere after 11.7 Fix from $1,9502024-10-31 MEDIUM 5.5 CVE-2024-50354 gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verificatio… Gnark 0.12.0+ Fix from $1,6002024-10-31 HIGH 7.5 CVE-2024-31152EPSS 18% The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafte… Wbr 6012 Firmware No fix yet Fix from $1,9502024-10-30 HIGH 7.5 CVE-2024-10466 By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vul… Firefox 128.4.0 / 132.0+ Fix from $1,9502024-10-29 HIGH 7.5 CVE-2024-49767 Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a versi… Quart 0.19.7 / 3.0.6+ Fix from $1,9502024-10-25 MEDIUM 5.3 CVE-2024-20526 A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a deni… Adaptive Security Appliance Software Mitigation only Fix from $1,6002024-10-23 HIGH 7.5 CVE-2024-20351 A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco Fire… Secure Firewall Threat Defense Mitigation only Fix from $1,9502024-10-23 HIGH 7.5 CVE-2024-21536 Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an Unhandled… Http Proxy Middleware 2.0.7 / 3.0.3+ Fix from $1,9502024-10-19 MEDIUM 6.5 CVE-2024-21230 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior,… MySQL after 8.4.2 Fix from $1,6002024-10-15 MEDIUM 6.5 CVE-2024-21196 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 and prior, … MySQL after 8.4.2 Fix from $1,6002024-10-15 MEDIUM 6.5 CVE-2024-45736 In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a … Splunk 9.1.6 / 9.1.2312.111+ Fix from $1,6002024-10-14 MEDIUM 6.5 CVE-2024-8184 There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-o… Jetty 9.4.56 / 10.0.24+ Fix from $1,6002024-10-14 MEDIUM 6.5 CVE-2024-6762 Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory. Jetty 10.0.18 / 11.0.18+ Fix from $1,6002024-10-14 HIGH 7.5 CVE-2024-9823 There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attac… Active Iq Unified Manager 9.4.54 / 10.0.18+ Fix from $1,9502024-10-14 HIGH 7.5 CVE-2024-47497 An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and E… Junos 21.4+ Fix from $1,9502024-10-11 MEDIUM 6.5 CVE-2024-7294 In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limit… Telerik Reporting 10.2.24.806+ Fix from $1,6002024-10-09 HIGH 7.5 CVE-2024-43575 Windows Hyper-V Denial of Service Vulnerability Windows Server 2016 10.0.14393.7428 / 10.0.17763.6414+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-43544 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability Windows Server 2008 10.0.14393.7428 / 10.0.17763.6414+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-43545 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Server 2008 10.0.14393.7428 / 10.0.17763.6414+ Fix from $1,9502024-10-08