Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2023-50966
erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2…
Mitigation only
HIGH 7.5
CVE-2024-26369
An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWrit…
Patch available
MEDIUM 6.5
CVE-2024-27085
Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite others can inject arbitrarily la…
Discourse
3.2.0 / 3.3.0+
MEDIUM 6.5
CVE-2024-27100
Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, silencing users and exporting…
Discourse
3.2.1 / 3.3.0+
HIGH 7.5
CVE-2024-24827
Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it makes it easier for an attacker…
Discourse
3.2.0 / 3.3.0+
HIGH 7.5
CVE-2024-28854
tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-listener, a malicious user can…
Tls Listener
0.10.0+
MEDIUM 6.5
CVE-2024-28053
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an …
Mattermost Server
8.1.10+
MEDIUM 6.5
CVE-2024-24975
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the…
Mattermost Mobile
2.13.0+
MEDIUM 6.8
CVE-2023-35191
Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of service via net…
Mitigation only
MEDIUM 5.3
CVE-2024-1410
Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excess…
Quiche
0.19.2+
HIGH 7.5
CVE-2024-1765
Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usa…
Quiche
0.19.2+
HIGH 7.5
CVE-2024-26190
Microsoft QUIC Denial of Service Vulnerability
.net
7.0.17 / 7.3.12+
HIGH 7.5
CVE-2024-21392
.NET and Visual Studio Denial of Service Vulnerability
.net
7.0.17 / 7.3.12+
MEDIUM 5.9
CVE-2024-28176
jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Enc…
Fedora
2.0.7 / 4.15.5+
MEDIUM 6.8
CVE-2024-28122
JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a t…
Jwx
1.2.29 / 2.0.21+
HIGH 7.8
CVE-2024-23265
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4,…
Ipados
1.1 / 10.4+
MEDIUM 6.5
CVE-2024-23259
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Proce…
Ipados
14.4 / 16.7.6+
HIGH 7.8
CVE-2023-52602
In the Linux kernel, the following vulnerability has been resolved:
jfs: fix slab-out-of-bounds Read in dtSearch
Currently while searching for curr…
Linux Kernel
4.19.307 / 5.4.269+
MEDIUM 5.3
CVE-2024-25615
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exp…
Arubaos
8.10.0.10 / 8.11.2.1+
HIGH 7.5
CVE-2024-25269
libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.
Libheif
after 1.17.6
HIGH 7.5
CVE-2024-27354
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate c…
Debian Linux
1.0.23 / 2.0.47+
HIGH 7.5
CVE-2024-27355
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a ce…
Debian Linux
1.0.23 / 2.0.47+
MEDIUM 6.5
CVE-2024-24988
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very lon…
Mattermost Server
8.1.8 / 9.1.5+
HIGH 8.6
CVE-2024-20321
A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker…
Nx Os
Mitigation only
MEDIUM 5.3
CVE-2024-20344
A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could …
Imm Management Package
1.0.11-1582+
MEDIUM 6.5
CVE-2023-51775
The jose4j component before 0.9.4 for Java allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Jose4j
0.9.4+
HIGH 7.5
CVE-2024-26141
Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Respo…
Rack
2.2.8.1 / 3.0.9.1+
HIGH 8.2
CVE-2021-47023
In the Linux kernel, the following vulnerability has been resolved:
net: marvell: prestera: fix port event handling on init
For some reason there m…
Linux Kernel
5.10.37 / 5.11.21+
HIGH 7.8
CVE-2021-47010
In the Linux kernel, the following vulnerability has been resolved:
net: Only allow init netns to set default tcp cong to a restricted algo
tcp_set…
Linux Kernel
4.19.191 / 5.4.119+
MEDIUM 5.5
CVE-2021-46939
In the Linux kernel, the following vulnerability has been resolved:
tracing: Restructure trace_clock_global() to never block
It was reported that a…
Linux Kernel
4.4.269 / 4.9.269+