Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 5.5 CVE-2023-49557 An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.… Yasm No fix yet Fix from $1,6002024-01-03 HIGH 7.5 CVE-2023-49550 An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component. Mjs No fix yet Fix from $1,9502024-01-02 MEDIUM 5.9 CVE-2023-50019 An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handli… Open5gs Patch available Fix from $1,6002024-01-02 HIGH 7.5 CVE-2023-50020 An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF. Open5gs Patch available Fix from $1,9502024-01-02 HIGH 7.5 CVE-2023-26157 Versions of the package libredwg before 0.12.5.6384 are vulnerable to Denial of Service (DoS) due to an out-of-bounds read involving section->num_pag… Libredwg 0.12.5.6384+ Fix from $1,9502024-01-02 HIGH 7.5 CVE-2023-50730 Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification requires that GraphQL fragments must… Grackle 0.18.0+ Fix from $1,9502023-12-22 HIGH 7.5 CVE-2023-46131 Grails is a framework used to build web applications with the Groovy programming language. A specially crafted web request can lead to a JVM crash or… Grails 3.3.17 / 4.1.3+ Fix from $1,9502023-12-21 HIGH 7.5 CVE-2023-50249 Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry'… Astro 7.87.0+ Fix from $1,9502023-12-20 HIGH 7.5 CVE-2023-50707 Through the exploitation of active user sessions, an attacker could send custom requests to cause a denial-of-service condition on the device. Bcu 500 Firmware No fix yet Fix from $1,9502023-12-20 MEDIUM 6.5 CVE-2023-46104 Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.… Superset 2.1.3 / 3.0.1+ Fix from $1,6002023-12-19 HIGH 7.5 CVE-2023-41151 An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the… Opc after 6.20.1 Fix from $1,9502023-12-14 MEDIUM 5.3 CVE-2023-6193 quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resou… Quiche after 0.19.0 Fix from $1,6002023-12-12 HIGH 7.5 CVE-2023-41963 Denial-of-service (DoS) vulnerability exists in FTP service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packe… Gc A22w Cw Firmware Mitigation only Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-49140 Denial-of-service (DoS) vulnerability exists in commplex-link service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially cra… Gc A22w Cw Firmware Mitigation only Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-49143 Denial-of-service (DoS) vulnerability exists in rfe service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted packe… Gc A22w Cw Firmware Mitigation only Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-49713 Denial-of-service (DoS) vulnerability exists in NetBIOS service of HMI GC-A2 series. If a remote unauthenticated attacker sends a specially crafted p… Gc A22w Cw Firmware Mitigation only Fix from $1,9502023-12-12 MEDIUM 6.5 CVE-2023-49809 Mattermost fails to handle a null request body in the /add endpoint, allowing a simple member to send a request with null request body to that endpoi… Mattermost Server after 9.1.0 Fix from $1,6002023-12-12 HIGH 7.5 CVE-2023-45847 Mattermost fails to to check the length when setting the title in a run checklist in Playbooks, allowing an attacker to send a specially crafted requ… Mattermost Server after 9.2.1 Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-49800 `nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no f… Nuxt Api Party after 0.21.3 Fix from $1,9502023-12-09 HIGH 7.5 CVE-2023-4486 Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC e… Nae55 Firmware 12.0.4+ Fix from $1,9502023-12-07 MEDIUM 5.3 CVE-2023-35909 Uncontrolled Resource Consumption vulnerability in Saturday Drive Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress leading to … Ninja Forms 3.6.26+ Fix from $1,6002023-12-07 HIGH 7.5 CVE-2023-48840 A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion. Appointment Scheduler No fix yet Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-48831 A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. Availability Booking Calendar No fix yet Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-48833 A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion. Time Slots Booking Calendar No fix yet Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-48834 A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion. Car Rental Script No fix yet Fix from $1,9502023-12-07 MEDIUM 5.3 CVE-2023-6180 The tokio-boring library in version 4.0.0 is affected by a memory leak issue that can lead to excessive resource consumption and potential DoS by res… Boring Mitigation only Fix from $1,6002023-12-05 HIGH 7.5 CVE-2023-39248 Dell OS10 Networking Switches running 10.5.2.x and above contain an Uncontrolled Resource Consumption (Denial of Service) vulnerability, when switche… Networking Os10 Mitigation only Fix from $1,9502023-12-05 MEDIUM 5.3 CVE-2023-49290 lestrrat-go/jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. A p2c parameter set too high in … Jwx 1.2.27 / 2.0.18+ Fix from $1,6002023-12-05 HIGH 7.5 CVE-2023-47633 Traefik is an open source HTTP reverse proxy and load balancer. The traefik docker container uses 100% CPU when it serves as its own backend, which i… Traefik after 2.10.5 Fix from $1,9502023-12-04 HIGH 7.5 CVE-2023-40692 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, 11.5 is vulnerable to denial of service under extreme stress conditions… Db2 Patch available Fix from $1,9502023-12-04