Vulnerability index

Browse CVEs

3,124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Resource ConsumptionCWE-400 × clear
HIGH 7.5 CVE-2021-21293 blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core before version 0.14.15 are a… Blaze 0.14.15+ Fix from $1,9502021-02-02 HIGH 7.5 CVE-2021-21294 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, 0.22.0-M2, and 1.0.0-M14 have… Http4s 0.21.17+ Fix from $1,9502021-02-02 MEDIUM 6.5 CVE-2021-21285 In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the doc… Docker 19.03.15 / 20.10.3+ Fix from $1,6002021-02-02 MEDIUM 5.3 CVE-2020-28493 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its u… Fedora 2.11.3+ Fix from $1,6002021-02-01 MEDIUM 6.5 CVE-2021-21254 CKEditor 5 is an open source rich text editor framework with a modular architecture. The CKEditor 5 Markdown plugin (@ckeditor/ckeditor5-markdown-gfm… Ckeditor5 25.0.0+ Fix from $1,6002021-01-29 HIGH 7.5 CVE-2021-25909 ZIV Automation 4CCT-EA6-334126BF firmware version 3.23.80.27.36371, allows an unauthenticated, remote attacker to cause a denial of service condition… 4cct Ea6 334126bf Firmware Mitigation only Fix from $1,9502021-01-29 MEDIUM 5.3 CVE-2021-20185 It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which co… Moodle 3.5.16 / 3.8.7+ Fix from $1,6002021-01-28 MEDIUM 5.5 CVE-2021-25224 A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a de… Serverprotect Patch available Fix from $1,6002021-01-27 MEDIUM 5.5 CVE-2021-25225 A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a de… Serverprotect Patch available Fix from $1,6002021-01-27 MEDIUM 5.5 CVE-2021-25226 A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cause a de… Serverprotect Patch available Fix from $1,6002021-01-27 MEDIUM 6.5 CVE-2021-21271 Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - written in any programming langua… Tendermint after 0.34.2 Fix from $1,6002021-01-26 HIGH 7.5 CVE-2020-27295 The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA T… Opc Ua Tunneller 6.3.0.8233+ Fix from $1,9502021-01-26 MEDIUM 6.5 CVE-2020-8293 A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and… Nextcloud Server 18.0.11 / 19.0.5+ Fix from $1,6002021-01-26 HIGH 7.5 CVE-2020-8295 A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user. Nextcloud Server 20.0.0+ Fix from $1,9502021-01-26 HIGH 7.5 CVE-2020-4766 IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consum… Mq Internet Pass Thru Patch available Fix from $1,9502021-01-22 HIGH 7.5 CVE-2021-1312 A vulnerability in the system resource management of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to cause… Elastic Services Controller after 5.3.0.94 Fix from $1,9502021-01-20 MEDIUM 6.5 CVE-2021-0215 On Juniper Networks Junos EX series, QFX Series, MX Series and SRX branch series devices, a memory leak occurs every time the 802.1X authenticator po… Junos No fix yet Fix from $1,6002021-01-15 HIGH 7.5 CVE-2021-0202 On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB)… Junos Mitigation only Fix from $1,9502021-01-15 HIGH 7.5 CVE-2021-22166 An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method GitLab 13.7.2+ Fix from $1,9502021-01-15 MEDIUM 6.5 CVE-2021-22168 A regular expression denial of service issue has been discovered in NuGet API affecting all versions of GitLab starting from version 12.8. GitLab 13.5.6 / 13.6.4+ Fix from $1,6002021-01-15 HIGH 7.5 CVE-2021-21252 The jQuery Validation Plugin provides drop-in validation for your existing forms. It is published as an npm package "jquery-validation". jquery-valid… Jquery Validation 1.19.3+ Fix from $1,9502021-01-13 HIGH 7.5 CVE-2020-36048 Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport. Engine.io 4.0.0+ Fix from $1,9502021-01-08 MEDIUM 5.5 CVE-2021-21236 CairoSVG is a Python (pypi) package. CairoSVG is an SVG converter based on Cairo. In CairoSVG before version 2.5.1, there is a regular expression den… Cairosvg 2.5.1+ Fix from $1,6002021-01-06 MEDIUM 6.5 CVE-2021-21235 kamadak-exif is an exif parsing library written in pure Rust. In kamadak-exif version 0.5.2, there is an infinite loop in parsing crafted PNG files. … Kamadak Exif Patch available Fix from $1,6002021-01-06 MEDIUM 6.5 CVE-2020-29490 Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a Denial of Service vulnerability on NAS Servers with NFS exports. A r… Emc Unity Operating Environment 5.0.4.0.5.012+ Fix from $1,6002021-01-05 HIGH 7.5 CVE-2020-35857 An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption. Trust Dns Server 0.18.1+ Fix from $1,9502020-12-31 MEDIUM 5.5 CVE-2020-35916 An issue was discovered in the image crate before 0.23.12 for Rust. A Mutable reference has immutable provenance. (In the case of LLVM, the IR may be… Image 0.23.12+ Fix from $1,6002020-12-31 HIGH 7.5 CVE-2020-26289 date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsin… Date And Time 0.14.2+ Fix from $1,9502020-12-28 MEDIUM 6.5 CVE-2020-27722 In BIG-IP APM versions 15.0.0-15.0.1.3, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, under certain conditions, the VDI plugin does not observe plugin flow-con… Big Ip Access Policy Manager 13.1.3.5 / 14.1.3.1+ Fix from $1,6002020-12-24 MEDIUM 6.5 CVE-2020-27724 In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on sy… Big Ip Access Policy Manager 13.1.3.5 / 14.1.3.1+ Fix from $1,6002020-12-24