Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2022-2053 When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementat… Integration Camel K 2.2.19+ Fix from $1,9502022-08-05 HIGH 7.5 CVE-2022-35236 In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server,… Big Ip Access Policy Manager 14.1.5 / 15.1.6.1+ Fix from $1,9502022-08-04 MEDIUM 6.5 CVE-2022-35241 In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resou… Nginx Instance Manager 2.3.1+ Fix from $1,6002022-08-04 HIGH 7.5 CVE-2022-33203 In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent… Big Ip Access Policy Manager 14.1.5 / 15.1.6.1+ Fix from $1,9502022-08-04 HIGH 7.5 CVE-2022-35923 v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowerc… V8n 1.5.1+ Fix from $1,9502022-08-02 HIGH 7.5 CVE-2022-35922 Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memo… Fedora 0.26.5+ Fix from $1,9502022-08-01 MEDIUM 5.3 CVE-2022-35915 OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbo… Contracts 4.7.2+ Fix from $1,6002022-08-01 HIGH 7.5 CVE-2022-31173 Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resulting in a program crash. Thi… Juniper 0.15.10+ Fix from $1,9502022-08-01 HIGH 7.5 CVE-2021-22642 An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. Twinsoft 1.46 / 12.4+ Fix from $1,9502022-07-28 HIGH 7.5 CVE-2022-24294 A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resource consumption. The bug coul… Mxnet 1.9.1+ Fix from $1,9502022-07-24 HIGH 7.5 CVE-2020-21405 An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk H96 Pro Plus Firmware No fix yet Fix from $1,9502022-07-20 HIGH 7.5 CVE-2022-27937 Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264. Pexip Infinity 27.3+ Fix from $1,9502022-07-17 MEDIUM 6.5 CVE-2022-2406 The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenti… Mattermost after 6.5.1 Fix from $1,6002022-07-14 MEDIUM 6.5 CVE-2022-31075 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-31078 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-31079 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 MEDIUM 6.5 CVE-2022-31080 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 HIGH 7.5 CVE-2022-31073 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,9502022-07-11 MEDIUM 6.5 CVE-2022-31074 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.… Kubeedge 1.9.4 / 1.10.2+ Fix from $1,6002022-07-11 HIGH 7.5 CVE-2022-30791 In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new TCP connections… Control For Beaglebone 4.5.0.0 / 4.6.0.0+ Fix from $1,9502022-07-11 HIGH 7.5 CVE-2022-30792 In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker to block new communicati… Control For Beaglebone 4.5.0.0 / 4.6.0.0+ Fix from $1,9502022-07-11 MEDIUM 6.5 CVE-2022-20808 A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS… Smart Software Manager On Prem 8-202112+ Fix from $1,6002022-07-06 HIGH 7.5 CVE-2022-31129 moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an ine… Fedora 2.29.4+ Fix from $1,9502022-07-06 HIGH 7.5 CVE-2022-30591 quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTT… Quic Go after 0.27.0 Fix from $1,9502022-07-06 HIGH 7.5 CVE-2014-3648 The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is use… Jboss Aerogear Mitigation only Fix from $1,9502022-07-01 HIGH 7.5 CVE-2022-31110 RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to the `filter` and `filterout`… Rsshub 2022-06-21+ Fix from $1,9502022-06-29 HIGH 7.5 CVE-2022-26477 The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered wi… Systemds after 2.2.1 Fix from $1,9502022-06-27 MEDIUM 6.5 CVE-2022-31016 Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption… Argo Cd 2.1.16 / 2.2.10+ Fix from $1,6002022-06-25 MEDIUM 5.3 CVE-2022-31803 In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated attacker to consume all avail… Gateway 2.3.9.38+ Fix from $1,6002022-06-24 HIGH 7.5 CVE-2022-29864 OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Reso… Ua .net Standard Stack 1.4.368.58+ Fix from $1,9502022-06-16