Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2021-21267 Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before version 2.0.0, email address va… Schema Inspector 2.0.0+ Fix from $1,9502021-03-19 HIGH 7.5 CVE-2021-28089 Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001. Fedora 0.3.5.14 / 0.4.4.8+ Fix from $1,9502021-03-19 HIGH 7.5 CVE-2020-27827 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle speci… Openshift Container Platform 1.0.8 / 2.6.9+ Fix from $1,9502021-03-18 MEDIUM 6.5 CVE-2021-21375 PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S… Debian Linux after 2.10 Fix from $1,6002021-03-10 MEDIUM 6.5 CVE-2020-35233 The TFTP server fails to handle multiple connections on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices, and allows external attackers to force device re… Gs116e Firmware Mitigation only Fix from $1,6002021-03-10 MEDIUM 5.5 CVE-2021-20265 A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw … Linux Kernel after 7.7.1 Fix from $1,6002021-03-10 MEDIUM 6.5 CVE-2021-21369 Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 there is a denial-of-service vu… Besu 1.5.1+ Fix from $1,6002021-03-09 HIGH 7.5 CVE-2021-22883EPSS 74% Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownP… Node.js 9.2.6.0 / 10.24.0+ Fix from $1,9502021-03-03 MEDIUM 5.5 CVE-2021-25252 Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to de… Apex Central Patch available Fix from $1,6002021-03-03 MEDIUM 5.3 CVE-2020-27223EPSS 78% In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers … Nifi 9.4.36+ Fix from $1,6002021-02-26 MEDIUM 6.5 CVE-2021-21274 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging… Fedora 1.25.0+ Fix from $1,6002021-02-26 HIGH 7.5 CVE-2020-24686 The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing rem… Pm554 Firmware Mitigation only Fix from $1,9502021-02-26 MEDIUM 5.3 CVE-2021-21328 Vapor is a web framework for Swift. In Vapor before version 4.40.1, there is a DoS attack against anyone who Bootstraps a metrics backend for their V… Vapor 4.40.1+ Fix from $1,6002021-02-26 HIGH 7.5 CVE-2020-27782 A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings… Jboss Fuse Mitigation only Fix from $1,9502021-02-23 HIGH 7.5 CVE-2021-22882 UniFi Protect before v1.17.1 allows an attacker to use spoofed cameras to perform a denial-of-service attack that may cause the UniFi Protect control… Unifi Protect Controller 1.17.1+ Fix from $1,9502021-02-23 HIGH 7.5 CVE-2020-11270 Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM parameter IE in Sna… Aqt1000 Firmware No fix yet Fix from $1,9502021-02-22 HIGH 7.5 CVE-2021-27405 A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for Node.js. Scrapbox Parser 6.0.3+ Fix from $1,9502021-02-19 HIGH 7.5 CVE-2020-28496 This affects the package three before 0.125.0. This can happen when handling rgb or hsl colors. PoC: var three = require('three') function build_blan… Three 0.125.0+ Fix from $1,9502021-02-18 HIGH 7.5 CVE-2021-1378 A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device t… Staros after 21.19.10 Fix from $1,9502021-02-17 MEDIUM 5.5 CVE-2020-24504 Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to po… Ethernet Network Adapter E810 Firmware 1.0.4+ Fix from $1,6002021-02-17 HIGH 7.5 CVE-2021-22553 Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the … Gerrit 2.15.22 / 2.16.26+ Fix from $1,9502021-02-17 MEDIUM 5.3 CVE-2021-21317 uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In uap-core before version 0.11.0… Uap Core 0.11.0+ Fix from $1,6002021-02-16 HIGH 7.5 CVE-2020-13949EPSS 7% In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leadin… Hive 4.0.0+ Fix from $1,9502021-02-12 HIGH 7.5 CVE-2021-22985 On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malici… Big Ip Application Security Manager 11.6.5.2 / 12.1.5.3+ Fix from $1,9502021-02-12 HIGH 7.5 CVE-2021-22880 The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. C… Rails 5.2.4.5 / 6.0.3.5+ Fix from $1,9502021-02-11 HIGH 7.5 CVE-2020-35498EPSS 8% A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a special… Debian Linux 2.5.12 / 2.6.10+ Fix from $1,9502021-02-11 HIGH 7.5 CVE-2020-5023 IBM Spectrum Protect Plus 10.1.0 through 10.1.7 could allow a remote user to inject arbitrary data iwhich could cause the serivce to crash due to exc… Spectrum Protect Plus after 10.1.7 Fix from $1,9502021-02-10 HIGH 7.5 CVE-2021-21306 Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regul… Marked 2.0.0+ Fix from $1,9502021-02-08 HIGH 7.5 CVE-2021-21240 httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of … Httplib2 0.19.0+ Fix from $1,9502021-02-08 MEDIUM 6.5 CVE-2021-1266 A vulnerability in the REST API of Cisco Managed Services Accelerator (MSX) could allow an authenticated, remote attacker to cause a denial of servic… Managed Services Accelerator 3.10.0+ Fix from $1,6002021-02-04