Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified MEDIUM 6.5
CVE-2025-25186

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4…

Patch available
Fix from $1,600 2025-02-10
Linux Kernel MEDIUM 5.5
CVE-2025-21690

In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there'…

Fix: 5.15.178 / 6.1.128+
Fix from $1,600 2025-02-10
GitLab MEDIUM 6.5
CVE-2025-1072

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4…

Fix: 17.3.7 / 17.4.4+
Fix from $1,600 2025-02-07
James Server HIGH 7.5
CVE-2024-37358

Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthent…

Fix: 3.7.6 / 3.8.2+
Fix from $1,950 2025-02-06
Aspera Shares MEDIUM 6.5
CVE-2024-38316

IBM Aspera Shares 1.9.0 through 1.10.0 PL6 does not properly rate limit the frequency that an authenticated user can send emails, which could result …

Fix: 1.10.0+
Fix from $1,600 2025-02-05
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2025-24312

When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server or firewall rule or policy, …

Fix: 1.4.0 / 15.1.10.6.0.11.6+
Fix from $1,950 2025-02-05
GitLab HIGH 7.5
CVE-2024-2878EPSS 19%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and sta…

Fix: 16.9.7 / 16.10.5+
Fix from $1,950 2025-02-05
GitLab HIGH 7.5
CVE-2024-9631

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting f…

Fix: 17.2.9 / 17.3.5+
Fix from $1,950 2025-02-05
GitLab HIGH 7.5
CVE-2023-6386

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 pr…

Fix: 16.6.7 / 16.7.5+
Fix from $1,950 2025-02-05
Unclassified HIGH 7.5
CVE-2024-12705EPSS 18%

Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This i…

Mitigation only
Fix from $1,950 2025-01-29
Unclassified HIGH 7.5
CVE-2024-56316

In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenticated attackers to cause a pe…

Mitigation only
Fix from $1,950 2025-01-27
Ipados MEDIUM 5.5
CVE-2025-24127

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3…

Fix: 2.3 / 13.7.3+
Fix from $1,600 2025-01-27
macOS MEDIUM 5.5
CVE-2025-24112

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an unexpecte…

Fix: 14.7.3 / 15.3+
Fix from $1,600 2025-01-27
Ipados MEDIUM 5.5
CVE-2025-24086

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sono…

Fix: 2.3 / 11.3+
Fix from $1,600 2025-01-27
Ipados MEDIUM 6.5
CVE-2024-54497

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.3…

Fix: 2.2 / 11.2+
Fix from $1,600 2025-01-27
Unclassified MEDIUM 5.3
CVE-2025-0695

An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash o…

Mitigation only
Fix from $1,600 2025-01-27
Unclassified HIGH 7.5
CVE-2024-55195

An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (DoS) when the program to requ…

Mitigation only
Fix from $1,950 2025-01-23
Unclassified HIGH 7.5
CVE-2025-24033

@fastify/multipart is a Fastify plugin for parsing the multipart content-type. Prior to versions 8.3.1 and 9.0.3, the `saveRequestFiles` function doe…

Patch available
Fix from $1,950 2025-01-23
Kibana MEDIUM 6.5
CVE-2024-43708

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in …

Fix: 7.17.23 / 8.15.0+
Fix from $1,600 2025-01-23
M Files Server HIGH 7.5
CVE-2025-0635

Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computing resources in cert…

Fix: 25.1.14445.5+
Fix from $1,950 2025-01-23
Kibana MEDIUM 6.5
CVE-2024-52972

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot.…

Fix: 7.17.23 / 8.15.0+
Fix from $1,600 2025-01-23
Lunasvg HIGH 7.5
CVE-2024-57722

lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create.

No fix yet
Fix from $1,950 2025-01-23
Cilium MEDIUM 5.3
CVE-2025-23028

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 …

Fix: 1.14.18 / 1.15.12+
Fix from $1,600 2025-01-22
Mysql Cluster MEDIUM 6.5
CVE-2025-21518

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior,…

Fix: after 9.1.0
Fix from $1,600 2025-01-21
Mysql Server HIGH 7.5
CVE-2025-21521

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling). Supported versions that are affected are 8.0.39 and p…

Fix: after 9.0.1
Fix from $1,950 2025-01-21
Mysql Server MEDIUM 6.5
CVE-2025-21522

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.40 and prior, 8.…

Fix: after 9.1.0
Fix from $1,600 2025-01-21
Jd Edwards Enterpriseone Tools MEDIUM 6.5
CVE-2025-21509

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: 9.2.9.0+
Fix from $1,600 2025-01-21
Mysql Server MEDIUM 6.5
CVE-2025-21501

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior,…

Fix: after 9.1.0
Fix from $1,600 2025-01-21
Jd Edwards Enterpriseone Tools MEDIUM 6.5
CVE-2025-21508

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: 9.2.9.0+
Fix from $1,600 2025-01-21
Mysql Server MEDIUM 6.5
CVE-2025-21500

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior,…

Fix: after 9.1.0
Fix from $1,600 2025-01-21