Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
MEDIUM 5.5 CVE-2021-32013 SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishan… Sheetjs 21.2.4+ Fix from $1,6002021-07-19 MEDIUM 5.5 CVE-2021-32014 SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandle… Sheetjs 21.2.4+ Fix from $1,6002021-07-19 MEDIUM 6.5 CVE-2021-0292 An Uncontrolled Resource Consumption vulnerability in the ARP daemon (arpd) and Network Discovery Protocol (ndp) process of Juniper Networks Junos OS… Junos Os Evolved Mitigation only Fix from $1,6002021-07-15 HIGH 7.5 CVE-2021-0285 An uncontrolled resource consumption vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX4600 Series switches allows an attacker sendi… Junos Mitigation only Fix from $1,9502021-07-15 HIGH 7.5 CVE-2021-36716 A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to p… Is Email 1.0.1+ Fix from $1,9502021-07-14 MEDIUM 6.5 CVE-2020-20217 Mikrotik RouterOs before 6.47 (stable tree) suffers from an uncontrolled resource consumption vulnerability in the /nova/bin/route process. An authen… Routeros 6.47+ Fix from $1,6002021-07-08 HIGH 7.5 CVE-2021-32740 Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption … Addressable 2.8.0+ Fix from $1,9502021-07-06 HIGH 7.5 CVE-2021-22119EPSS 6% Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susceptible to a Denial-of-S… Spring Security 5.2.11 / 5.3.10+ Fix from $1,9502021-06-29 HIGH 7.5 CVE-2021-34549 An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an atta… Tor 0.3.5.15 / 0.4.4.9+ Fix from $1,9502021-06-29 HIGH 7.5 CVE-2021-33503 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority reg… Urllib3 1.26.5+ Fix from $1,9502021-06-29 MEDIUM 6.5 CVE-2021-32722 GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an uncontrolled resource consumpt… Globalnewfiles Patch available Fix from $1,6002021-06-28 MEDIUM 6.5 CVE-2021-32723 Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is us… Prism 1.24.0 / 21.1.4+ Fix from $1,6002021-06-28 MEDIUM 6.5 CVE-2021-32699 Wings is the control plane software for the open source Pterodactyl game management system. All versions of Pterodactyl Wings prior to `1.4.4` are vu… Wings 1.4.4+ Fix from $1,6002021-06-22 HIGH 7.5 CVE-2021-33824 An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which c… Mgate Mb3180 Firmware No fix yet Fix from $1,9502021-06-18 HIGH 7.5 CVE-2021-33818 An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, … Camera G3 Flex Firmware No fix yet Fix from $1,9502021-06-18 HIGH 7.5 CVE-2021-33822 An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E1_02.00_22. Attackers can use slowhttptest tool to send incomplete HTTP request, which co… 4gee Router Hh70vb Firmware No fix yet Fix from $1,9502021-06-18 MEDIUM 6.5 CVE-2020-8299 Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WA… Gateway 10.2.9a / 11.1.2c+ Fix from $1,6002021-06-16 HIGH 7.5 CVE-2021-30468EPSS 7% A vulnerability in the JsonMapObjectReaderWriter of Apache CXF allows an attacker to submit malformed JSON to a web service, which results in the thr… Cxf 3.3.11 / 3.4.4+ Fix from $1,9502021-06-16 HIGH 7.5 CVE-2021-22902 The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffers from a possible denial of … Rails 6.0.3.7 / 6.1.0.2+ Fix from $1,9502021-06-11 HIGH 7.5 CVE-2021-22904 The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication l… Rails 5.2.4.6 / 5.2.6+ Fix from $1,9502021-06-11 MEDIUM 6.5 CVE-2021-22906 Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated user… End To End Encryption 1.5.3 / 1.6.3+ Fix from $1,6002021-06-11 MEDIUM 6.5 CVE-2021-22181 A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship an… GitLab 13.10.5 / 13.11.5+ Fix from $1,6002021-06-11 HIGH 7.5 CVE-2021-20591 Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN… R00cpu Firmware Mitigation only Fix from $1,9502021-06-11 MEDIUM 5.5 CVE-2020-12291 Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of servic… Jhl6240 Thunderbolt 3 Firmware 21 / 22+ Fix from $1,6002021-06-09 MEDIUM 5.5 CVE-2020-12296 Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of servic… Dsl5320 Thunderbolt 2 Firmware 21 / 22+ Fix from $1,6002021-06-09 MEDIUM 6.5 CVE-2021-22216 A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker to cause uncontrolled resourc… GitLab 13.10.5 / 13.11.5+ Fix from $1,6002021-06-08 HIGH 7.5 CVE-2021-31340 A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2), SIMATIC … Simatic Rf166c Firmware 1.3.2 / 2.0+ Fix from $1,9502021-06-08 MEDIUM 5.5 CVE-2021-26945 An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an appl… Openexr 3.0.1+ Fix from $1,6002021-06-08 HIGH 7.5 CVE-2021-22116 RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection e… Rabbitmq 3.8.16+ Fix from $1,9502021-06-08 MEDIUM 5.5 CVE-2021-23215 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this … Fedora 3.0.1+ Fix from $1,6002021-06-08