Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2021-31409 Unsafe validation RegEx in EmailValidator component in com.vaadin:vaadin-compatibility-server versions 8.0.0 through 8.12.4 (Vaadin versions 8.0.0 th… Vaadin after 8.12.4 Fix from $1,9502021-05-06 HIGH 7.5 CVE-2021-1275 Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to… Catalyst Sd Wan Manager 20.3.3 / 20.4.1+ Fix from $1,9502021-05-06 HIGH 7.5 CVE-2020-28944 OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data. Ox Guard after 2.10.4 Fix from $1,9502021-04-30 MEDIUM 6.5 CVE-2021-1489 A vulnerability in filesystem usage management for Cisco Firepower Device Manager (FDM) Software could allow an authenticated, remote attacker to exh… Firepower Device Manager 6.4.0.12 / 6.6.4+ Fix from $1,6002021-04-29 MEDIUM 6.5 CVE-2021-21391 CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5-font, ckeditor5-image, ckedi… Ckeditor5 Engine 27.0.0+ Fix from $1,6002021-04-29 HIGH 7.5 CVE-2021-29469 Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages co… Redis 3.1.1+ Fix from $1,9502021-04-23 HIGH 7.5 CVE-2020-36320 Unsafe validation RegEx in EmailValidator class in com.vaadin:vaadin-server versions 7.0.0 through 7.7.21 (Vaadin 7.0.0 through 7.7.21) allows attack… Vaadin 7.7.22+ Fix from $1,9502021-04-23 HIGH 7.5 CVE-2021-31405 Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadin 14.0.6 through 14.4.3), and… Flow 2.3.3 / 4.0.3+ Fix from $1,9502021-04-23 MEDIUM 6.5 CVE-2021-0257 On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPCs (Modular Port Concentrators) where Integrated Routing and Bridging (IR… Junos Mitigation only Fix from $1,6002021-04-22 MEDIUM 5.3 CVE-2021-0229 An uncontrolled resource consumption vulnerability in Message Queue Telemetry Transport (MQTT) server of Juniper Networks Junos OS allows an attacker… Junos Mitigation only Fix from $1,6002021-04-22 HIGH 7.5 CVE-2021-0230 On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interfac… Junos Mitigation only Fix from $1,9502021-04-22 HIGH 7.5 CVE-2021-0233 A vulnerability in Juniper Networks Junos OS ACX500 Series, ACX4000 Series, may allow an attacker to cause a Denial of Service (DoS) by sending a hig… Junos Mitigation only Fix from $1,9502021-04-22 MEDIUM 5.5 CVE-2021-0238 When a MX Series is configured as a Broadband Network Gateway (BNG) based on Layer 2 Tunneling Protocol (L2TP), executing certain CLI command may cau… Junos Mitigation only Fix from $1,6002021-04-22 HIGH 7.5 CVE-2021-30464 OMICRON StationGuard before 1.10 allows remote attackers to cause a denial of service (connectivity outage) via crafted tcp/20499 packets to the CTRL… Stationguard 1.10+ Fix from $1,9502021-04-20 MEDIUM 6.5 CVE-2021-29453 matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle … Matrix Media Repo 1.2.7+ Fix from $1,6002021-04-19 HIGH 7.5 CVE-2021-29430 Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send a… Sydent 2.3.0+ Fix from $1,9502021-04-15 MEDIUM 5.3 CVE-2021-21728 A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker can consume system processing resources… Zxa10 C300m Firmware 4.5+ Fix from $1,6002021-04-09 MEDIUM 5.5 CVE-2021-21529 Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low privileges… System Update 1.9+ Fix from $1,6002021-04-02 HIGH 7.5 CVE-2021-22696EPSS 7% CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization F… Cxf 3.3.10 / 3.4.3+ Fix from $1,9502021-04-02 HIGH 7.5 CVE-2021-28165EPSS 54% In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS f… Jenkins 2.277.3 / 2.286+ Fix from $1,9502021-04-01 MEDIUM 6.5 CVE-2021-20234 An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a … Libzmq 4.3.3+ Fix from $1,6002021-04-01 MEDIUM 5.5 CVE-2021-3478 There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processe… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 MEDIUM 5.5 CVE-2021-3479 There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processe… Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 MEDIUM 5.3 CVE-2018-1107 It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email f… Is My Json Valid 1.4.1 / 2.17.2+ Fix from $1,6002021-03-30 MEDIUM 5.3 CVE-2018-1109 A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression … Braces 2.3.1+ Fix from $1,6002021-03-30 HIGH 7.5 CVE-2021-20216 A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of servic… Privoxy 3.0.31+ Fix from $1,9502021-03-25 HIGH 7.5 CVE-2021-1460 A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial IS… iOS 1.3.2 / 1.12.0.3+ Fix from $1,9502021-03-24 HIGH 7.5 CVE-2019-19343 A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holdi… Jboss Remoting 2.0.25 / 5.0.14+ Fix from $1,9502021-03-23 HIGH 7.5 CVE-2021-21348EPSS 14% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a re… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23 HIGH 7.5 CVE-2021-21341EPSS 78% XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remo… Activemq 1.4.16 / 5.5+ Fix from $1,9502021-03-23