Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-2053
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementat…
Integration Camel K
2.2.19+
HIGH 7.5
CVE-2022-35236
In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server,…
Big Ip Access Policy Manager
14.1.5 / 15.1.6.1+
MEDIUM 6.5
CVE-2022-35241
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resou…
Nginx Instance Manager
2.3.1+
HIGH 7.5
CVE-2022-33203
In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent…
Big Ip Access Policy Manager
14.1.5 / 15.1.6.1+
HIGH 7.5
CVE-2022-35923
v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowerc…
V8n
1.5.1+
HIGH 7.5
CVE-2022-35922
Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memo…
Fedora
0.26.5+
MEDIUM 5.3
CVE-2022-35915
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbo…
Contracts
4.7.2+
HIGH 7.5
CVE-2022-31173
Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. Thi…
Juniper
0.15.10+
HIGH 7.5
CVE-2021-22642
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
Twinsoft
1.46 / 12.4+
HIGH 7.5
CVE-2022-24294
A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug coul…
Mxnet
1.9.1+
HIGH 7.5
CVE-2020-21405
An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk
H96 Pro Plus Firmware
No fix yet
HIGH 7.5
CVE-2022-27937
Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.
Pexip Infinity
27.3+
MEDIUM 6.5
CVE-2022-2406
The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenti…
Mattermost
after 6.5.1
MEDIUM 6.5
CVE-2022-31075
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 6.5
CVE-2022-31078
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 6.5
CVE-2022-31079
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 6.5
CVE-2022-31080
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
HIGH 7.5
CVE-2022-31073
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
MEDIUM 6.5
CVE-2022-31074
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…
Kubeedge
1.9.4 / 1.10.2+
HIGH 7.5
CVE-2022-30791
In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections…
Control For Beaglebone
4.5.0.0 / 4.6.0.0+
HIGH 7.5
CVE-2022-30792
In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communicati…
Control For Beaglebone
4.5.0.0 / 4.6.0.0+
MEDIUM 6.5
CVE-2022-20808
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS…
Smart Software Manager On Prem
8-202112+
HIGH 7.5
CVE-2022-31129
moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an ine…
Fedora
2.29.4+
HIGH 7.5
CVE-2022-30591
quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTT…
Quic Go
after 0.27.0
HIGH 7.5
CVE-2014-3648
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is use…
Jboss Aerogear
Mitigation only
HIGH 7.5
CVE-2022-31110
RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to the `filter` and `filterout`…
Rsshub
2022-06-21+
HIGH 7.5
CVE-2022-26477
The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered wi…
Systemds
after 2.2.1
MEDIUM 6.5
CVE-2022-31016
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption…
Argo Cd
2.1.16 / 2.2.10+
MEDIUM 5.3
CVE-2022-31803
In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all avail…
Gateway
2.3.9.38+
HIGH 7.5
CVE-2022-29864
OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Reso…
Ua .net Standard Stack
1.4.368.58+