Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-34109
zxcvbn-ts is an open source password strength estimator written in typescript. This vulnerability affects users running on the nodeJS platform which …
Zxcvbn Ts
3.0.2+
MEDIUM 5.7
CVE-2023-33957
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of s…
Notation Go
1.0.0+
MEDIUM 6.5
CVE-2023-33958
notation is a CLI tool to sign and verify OCI artifacts and container images. An attacker who has compromised a registry and added a high number of s…
Notation Go
1.0.0+
HIGH 7.5
CVE-2023-34104
fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sa…
Fast Xml Parser
4.2.4+
MEDIUM 5.5
CVE-2022-33303
Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queu…
Wcn685x 5 Firmware
Patch available
MEDIUM 6.5
CVE-2023-29544
If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentia…
Firefox
112.0+
MEDIUM 6.5
CVE-2023-0616
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which cou…
Thunderbird
102.8+
MEDIUM 5.5
CVE-2023-29735
An issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.
Edjing Mix
No fix yet
HIGH 7.5
CVE-2023-30570
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode pack…
Libreswan
after 4.10
MEDIUM 5.9
CVE-2023-28320
A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at…
Curl
8.1.0 / 11.7.9+
MEDIUM 5.5
CVE-2023-1981
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
Fedora
No fix yet
HIGH 7.5
CVE-2023-20883
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial…
Spring Boot
2.5.14+
MEDIUM 5.9
CVE-2023-20882
In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applicat…
Cf Deployment
0.266.0 / 29.0.0+
MEDIUM 6.5
CVE-2023-33720
mp4v2 v2.1.2 was discovered to contain a memory leak via the class MP4BytesProperty.
Mp4v2
No fix yet
MEDIUM 6.5
CVE-2022-39374
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joine…
Synapse
1.68.0+
HIGH 7.5
CVE-2023-32067
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malf…
Fedora
1.19.1+
HIGH 7.5
CVE-2023-2798
Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web p…
Htmlunit
2.70.0+
HIGH 7.5
CVE-2023-33980
Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a seri…
Briar
1.4.22+
MEDIUM 6.5
CVE-2023-26595
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service…
Garoon
after 5.9.2
HIGH 7.5
CVE-2023-33297
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inv…
Bitcoin Core
24.1+
HIGH 7.5
CVE-2023-2295
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptabl…
Enterprise Linux
Mitigation only
MEDIUM 5.3
CVE-2023-26044
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. Previous versions of ReactPHP's HTTP server component c…
Http
1.9.0+
MEDIUM 5.5
CVE-2023-20930
In pushDynamicShortcut of ShortcutPackage.java, there is a possible way to get the device into a boot loop due to resource exhaustion. This could lea…
Android
Patch available
HIGH 7.8
CVE-2023-21110
In several functions of SnoozeHelper.java, there is a possible way to grant notifications access due to resource exhaustion. This could lead to local…
Android
Patch available
HIGH 7.5
CVE-2023-32787
The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that the…
Ua Java Legacy
1.2.0 / 1.4.20+
HIGH 7.5
CVE-2023-23447
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows …
Ftmg Esd20axx Firmware
2.0+
HIGH 7.5
CVE-2023-31409
Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows …
Ftmg Esd20axx Firmware
2.0+
HIGH 7.5
CVE-2023-28356
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enter a hot l…
Rocket.chat
6.0.0+
HIGH 7.5
CVE-2022-36329
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Dig…
My Cloud Home Firmware
9.4.0-191+
HIGH 7.5
CVE-2023-25568
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is a…
Boxo
Patch available