Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2021-26260
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this …
Fedora
3.0.1+
MEDIUM 6.5
CVE-2020-1750
A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memo…
Machine Config Operator
4.2.36 / 4.3.25+
MEDIUM 6.5
CVE-2021-1563
Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance …
Video Surveillance 7530pd Firmware
2.12.3+
MEDIUM 6.5
CVE-2021-1564
Multiple vulnerabilities in the implementation of the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) for Cisco Video Surveillance …
Video Surveillance 7530pd Firmware
2.12.3+
HIGH 7.5
CVE-2020-28469
This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.
Glob Parent
5.1.2+
MEDIUM 5.9
CVE-2020-35510
A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB…
Jboss Remoting
5.0.20+
MEDIUM 5.9
CVE-2020-14340
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection c…
Xnio
3.7.9 / 3.8.2+
HIGH 7.5
CVE-2020-14326
A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with…
Integration Camel K
4.5.6+
HIGH 7.5
CVE-2021-33623
The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denial-of-service (ReDoS) for the …
Debian Linux
3.0.1 / 4.0.1+
MEDIUM 5.3
CVE-2021-20201
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumpt…
Enterprise Linux
0.14.92+
HIGH 7.5
CVE-2021-20237
An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauth…
Libzmq
4.3.3+
HIGH 7.5
CVE-2018-10868
redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user …
Certification
Mitigation only
MEDIUM 5.5
CVE-2020-25673
A vulnerability was found in Linux kernel where non-blocking socket in llcp_sock_connect() leads to leak and eventually hanging-up the system.
Linux Kernel
5.3.18+
MEDIUM 5.3
CVE-2021-32640
ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to…
Ws
6.2.2 / 7.4.6+
HIGH 7.5
CVE-2020-36332
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from th…
Enterprise Linux
1.0.1+
HIGH 7.5
CVE-2021-20718
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.
Fedora
21.3+
MEDIUM 5.5
CVE-2021-32617
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (…
Fedora
0.27.4+
MEDIUM 6.5
CVE-2021-32455
SITEL CAP/PRX firmware version 5.2.01, allows an attacker with access to the device´s network to cause a denial of service condition on the device. A…
Cap\/prx Firmware
Mitigation only
HIGH 7.5
CVE-2021-32816
ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Client before version 3.16.60 has …
Protonmail
3.16.60+
MEDIUM 6.5
CVE-2021-29506
GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vu…
Graphhopper
2.4+
MEDIUM 6.5
CVE-2021-22139
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the r…
Kibana
7.12.1+
HIGH 7.5
CVE-2021-32918
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memo…
Debian Linux
0.11.9+
HIGH 7.5
CVE-2021-27385
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…
Simatic Wincc Runtime Advanced
15.1 / 16+
HIGH 7.5
CVE-2020-25242
A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (incl. SIPLUS …
Simatic Net Cp 343 1 Advanced Firmware
Mitigation only
HIGH 7.5
CVE-2021-29509
Puma is a concurrent HTTP 1.1 server for Ruby/Rack applications. The fix for CVE-2019-16770 was incomplete. The original fix only protected existing …
Puma
4.3.8 / 5.3.1+
MEDIUM 5.3
CVE-2021-29471
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging…
Fedora
1.33.2+
HIGH 7.5
CVE-2021-30504
In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
Intellij Idea
2021.1+
MEDIUM 5.3
CVE-2021-32053
JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests…
Hapi Fhir
5.4.0+
HIGH 7.5
CVE-2021-23011
On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.4, 12.1.x before 12.1.6, and 11.6.x before 11.6.5.…
Big Ip Access Policy Manager
11.6.5.3 / 12.1.6+
MEDIUM 5.3
CVE-2021-21419
Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. …
Fedora
0.31.0+