Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-41946
REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity expansions with SAX2 or pull…
Rexml
3.3.3+
HIGH 7.5
CVE-2024-41123
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has many specific characters suc…
Rexml
3.2.7 / 3.3.2+
MEDIUM 6.5
CVE-2022-4003
A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.
Q14 Firmware
1.5.0.16+
MEDIUM 6.5
CVE-2024-37281
An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously craft…
Kibana
7.17.23 / 8.14.0+
HIGH 7.5
CVE-2024-37299
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the…
Discourse
3.2.5+
HIGH 7.5
CVE-2024-41818
fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
Fast Xml Parser
Patch available
MEDIUM 5.5
CVE-2024-40575
An issue in Huawei Technologies opengauss (openGauss 5.0.0 build) v.7.3.0 allows a local attacker to cause a denial of service via the modification o…
Opengauss
No fix yet
MEDIUM 6.5
CVE-2024-3297
An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between two devices, as implemented …
Matter
Mitigation only
HIGH 7.5
CVE-2024-40634
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthent…
Argo Cd
2.9.20 / 2.10.15+
HIGH 7.5
CVE-2024-32007
An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of…
Cxf
3.5.9 / 3.6.4+
MEDIUM 6.5
CVE-2024-21177
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior …
Mysql Cluster
after 8.4.0
MEDIUM 6.5
CVE-2024-21171
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior …
MySQL
after 8.4.0
MEDIUM 5.5
CVE-2024-21163
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.37 and prior …
MySQL
after 8.0.37
MEDIUM 5.5
CVE-2024-21161
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…
Vm Virtualbox
7.0.20+
MEDIUM 5.8
CVE-2024-21126
Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.23 a…
Database Server
after 21.14
MEDIUM 6.5
CVE-2024-5795
A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sendi…
Enterprise Server
3.9.17 / 3.10.14+
MEDIUM 6.5
CVE-2023-39329
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a de…
Openjpeg
Mitigation only
HIGH 7.5
CVE-2024-39551
An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of Juniper Networks Junos OS on SRX Series and MX Se…
Junos
Mitigation only
HIGH 7.5
CVE-2024-39548
An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an unauthenticated, network-bas…
Junos Os Evolved
21.2+
CRITICAL 9.1
CVE-2024-6036EPSS 11%
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/q…
Chuanhuchatgpt
No fix yet
MEDIUM 6.5
CVE-2024-39557
An Uncontrolled Resource Consumption vulnerability in the
Layer 2 Address Learning Daemon (l2ald)
of Juniper Networks Junos OS Evolved allows an …
Junos Os Evolved
21.4+
HIGH 7.5
CVE-2024-39693
Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting t…
Next.js
13.5.0+
HIGH 7.5
CVE-2024-21523
All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. …
Mitigation only
HIGH 7.5
CVE-2024-21526
All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the S…
Mitigation only
HIGH 7.5
CVE-2024-21521
All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to se…
Mitigation only
HIGH 8.1
CVE-2024-29153
A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos…
Exynos 9820 Firmware
Mitigation only
MEDIUM 5.5
CVE-2024-5652
In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker…
Desktop
4.31.0+
HIGH 7.5
CVE-2024-38067
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows Server 2008
10.0.14393.7159 / 10.0.17763.6054+
HIGH 7.5
CVE-2024-38068
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows 10 1507
10.0.10240.20710 / 10.0.14393.7159+
HIGH 7.5
CVE-2024-38031
Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
Windows Server 2008
10.0.14393.7159 / 10.0.17763.6054+