Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2024-41946 REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull… Rexml 3.3.3+ Fix from $1,9502024-08-01 HIGH 7.5 CVE-2024-41123 REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters suc… Rexml 3.2.7 / 3.3.2+ Fix from $1,9502024-08-01 MEDIUM 6.5 CVE-2022-4003 A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request. Q14 Firmware 1.5.0.16+ Fix from $1,6002024-07-31 MEDIUM 6.5 CVE-2024-37281 An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously craft… Kibana 7.17.23 / 8.14.0+ Fix from $1,6002024-07-30 HIGH 7.5 CVE-2024-37299 Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the… Discourse 3.2.5+ Fix from $1,9502024-07-30 HIGH 7.5 CVE-2024-41818 fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1. Fast Xml Parser Patch available Fix from $1,9502024-07-29 MEDIUM 5.5 CVE-2024-40575 An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification o… Opengauss No fix yet Fix from $1,6002024-07-24 MEDIUM 6.5 CVE-2024-3297 An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented … Matter Mitigation only Fix from $1,6002024-07-24 HIGH 7.5 CVE-2024-40634 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthent… Argo Cd 2.9.20 / 2.10.15+ Fix from $1,9502024-07-22 HIGH 7.5 CVE-2024-32007 An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of… Cxf 3.5.9 / 3.6.4+ Fix from $1,9502024-07-19 MEDIUM 6.5 CVE-2024-21177 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior … Mysql Cluster after 8.4.0 Fix from $1,6002024-07-16 MEDIUM 6.5 CVE-2024-21171 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior … MySQL after 8.4.0 Fix from $1,6002024-07-16 MEDIUM 5.5 CVE-2024-21163 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior … MySQL after 8.0.37 Fix from $1,6002024-07-16 MEDIUM 5.5 CVE-2024-21161 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.20+ Fix from $1,6002024-07-16 MEDIUM 5.8 CVE-2024-21126 Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.23 a… Database Server after 21.14 Fix from $1,6002024-07-16 MEDIUM 6.5 CVE-2024-5795 A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sendi… Enterprise Server 3.9.17 / 3.10.14+ Fix from $1,6002024-07-16 MEDIUM 6.5 CVE-2023-39329 A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a de… Openjpeg Mitigation only Fix from $1,6002024-07-13 HIGH 7.5 CVE-2024-39551 An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of  Juniper Networks Junos OS on SRX Series and MX Se… Junos Mitigation only Fix from $1,9502024-07-11 HIGH 7.5 CVE-2024-39548 An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an unauthenticated, network-bas… Junos Os Evolved 21.2+ Fix from $1,9502024-07-11 CRITICAL 9.1 CVE-2024-6036EPSS 11% A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/q… Chuanhuchatgpt No fix yet Fix from $2,3002024-07-10 MEDIUM 6.5 CVE-2024-39557 An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an … Junos Os Evolved 21.4+ Fix from $1,6002024-07-10 HIGH 7.5 CVE-2024-39693 Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting t… Next.js 13.5.0+ Fix from $1,9502024-07-10 HIGH 7.5 CVE-2024-21523 All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. … Mitigation only Fix from $1,9502024-07-10 HIGH 7.5 CVE-2024-21526 All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the S… Mitigation only Fix from $1,9502024-07-10 HIGH 7.5 CVE-2024-21521 All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to se… Mitigation only Fix from $1,9502024-07-10 HIGH 8.1 CVE-2024-29153 A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos… Exynos 9820 Firmware Mitigation only Fix from $1,9502024-07-09 MEDIUM 5.5 CVE-2024-5652 In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker… Desktop 4.31.0+ Fix from $1,6002024-07-09 HIGH 7.5 CVE-2024-38067 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Server 2008 10.0.14393.7159 / 10.0.17763.6054+ Fix from $1,9502024-07-09 HIGH 7.5 CVE-2024-38068 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows 10 1507 10.0.10240.20710 / 10.0.14393.7159+ Fix from $1,9502024-07-09 HIGH 7.5 CVE-2024-38031 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability Windows Server 2008 10.0.14393.7159 / 10.0.17763.6054+ Fix from $1,9502024-07-09