Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2022-26372
On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11…
Big Ip Access Policy Manager
Mitigation only
HIGH 7.5
CVE-2022-20760
A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could a…
Secure Firewall Threat Defense
6.4.0.15 / 6.6.5.2+
HIGH 7.5
CVE-2022-22275
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially…
Sonicos
after 7.0.1-5030-r2007
MEDIUM 5.9
CVE-2021-43933
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a…
Roboguide
after 9.40083.00.05
HIGH 7.5
CVE-2022-24863
http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2…
Http Swagger
1.2.6+
MEDIUM 6.5
CVE-2022-20692
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a deni…
Ios Xe
Mitigation only
HIGH 7.5
CVE-2022-26498EPSS 16%
An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files cou…
Debian Linux
18.11.2+
MEDIUM 6.5
CVE-2022-22191
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos OS on the EX4300 switch, sent …
Junos
15.1+
HIGH 7.5
CVE-2021-41119
Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial of service attack via a crafte…
Wire Server
2022-03-01+
MEDIUM 6.5
CVE-2022-1337
The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authentica…
Mattermost Server
5.37.9 / 6.2.5+
HIGH 7.5
CVE-2022-21155
A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrServic…
Scada Server
after 3.77
HIGH 7.5
CVE-2022-27194
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions < V3.1 SP1), SINETPLAN (All versions), TIA Portal (V15,…
Simatic Pcs Neo
3.1+
HIGH 7.5
CVE-2022-25622
The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP…
Simatic Cfu Diq Firmware
2.0.0+
HIGH 7.5
CVE-2022-24836
Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to exce…
Nokogiri
1.13.4 / 13.1+
HIGH 7.5
CVE-2022-24839
org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryErro…
Nekohtml
1.9.22.noko2+
MEDIUM 6.5
CVE-2022-1210
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a m…
Libtiff
No fix yet
MEDIUM 5.7
CVE-2022-0489
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature w…
GitLab
14.6.5 / 14.8.2+
MEDIUM 5.3
CVE-2021-22100
In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or malici…
Capi Release
1.122.0 / 17.1.0+
HIGH 7.5
CVE-2022-24729
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plug…
Drupal
4.18.0 / 9.2.15+
HIGH 8.1
CVE-2022-22145
CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource consumption. CENTUM CS 3000 vers…
Centum Cs 3000 Firmware
Mitigation only
HIGH 7.5
CVE-2022-24726
Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, istiod, is vulnerable to a requ…
Istio
1.11.8 / 1.12.5+
MEDIUM 6.5
CVE-2021-3733
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser)…
Python
3.6.14 / 3.7.11+
MEDIUM 6.5
CVE-2022-24741
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uplo…
Nextcloud Server
21.0.8 / 22.2.4+
HIGH 7.5
CVE-2022-24464
.NET and Visual Studio Denial of Service Vulnerability
Fedora
16.7.26 / 16.9.18+
HIGH 7.5
CVE-2022-24713EPSS 14%
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service a…
Regex
1.5.5+
HIGH 7.5
CVE-2021-3737EPSS 12%
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP …
Python
3.6.14 / 3.7.11+
HIGH 7.5
CVE-2022-23328
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all …
Go Ethereum
No fix yet
MEDIUM 5.5
CVE-2022-25326
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem …
Fscrypt
after 0.3.2
HIGH 7.5
CVE-2021-4021
A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary …
Radare2
after 5.5.0
MEDIUM 5.5
CVE-2022-0695
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Fedora
5.6.4+