Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Kibana MEDIUM 6.5
CVE-2024-52973

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/log_entries/summa…

Fix: 7.17.23 / 8.14.2+
Fix from $1,600 2025-01-21
Elasticsearch HIGH 7.5
CVE-2024-43709

An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a special…

Fix: 7.17.21 / 8.13.3+
Fix from $1,950 2025-01-21
Txseries For Multiplatforms HIGH 7.5
CVE-2024-41742

IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operation…

Mitigation only
Fix from $1,950 2025-01-19
Txseries For Multiplatforms HIGH 7.5
CVE-2024-41743

IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocati…

Mitigation only
Fix from $1,950 2025-01-19
Safer Payments HIGH 7.5
CVE-2024-45662

IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denia…

Fix: 6.4.2.08 / 6.5.0.06+
Fix from $1,950 2025-01-18
Matrix Media Repo HIGH 7.5
CVE-2024-36403

Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded di…

Fix: 1.3.5+
Fix from $1,950 2025-01-16
Unclassified HIGH 7.5
CVE-2018-25108

An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption.

Mitigation only
Fix from $1,950 2025-01-16
Django HIGH 7.5
CVE-2024-56374

An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed…

Fix: 4.2.18 / 5.0.11+
Fix from $1,950 2025-01-14
Fortios MEDIUM 5.3
CVE-2024-46666

An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all vers…

Fix: 7.2.9 / 7.4.5+
Fix from $1,600 2025-01-14
Fortisiem HIGH 7.5
CVE-2024-46667

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, …

Fix: 7.1.6+
Fix from $1,950 2025-01-14
Fortios HIGH 7.5
CVE-2024-46668

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8…

Fix: 6.4.16 / 7.0.16+
Fix from $1,950 2025-01-14
Virtuoso HIGH 7.5
CVE-2024-57662

An issue in the sqlg_hash_source component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQ…

No fix yet
Fix from $1,950 2025-01-14
Virtuoso HIGH 7.5
CVE-2024-57663

An issue in the sqlg_place_dpipes component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted S…

No fix yet
Fix from $1,950 2025-01-14
Virtuoso HIGH 7.5
CVE-2024-57664

An issue in the sqlg_group_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL…

No fix yet
Fix from $1,950 2025-01-14
Exynos 1080 Firmware MEDIUM 6.5
CVE-2024-46921

An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W100…

Mitigation only
Fix from $1,600 2025-01-13
App Connect Enterprise Certified Container MEDIUM 5.5
CVE-2022-22491

IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12…

Fix: after 12.4
Fix from $1,600 2025-01-09
Next.js MEDIUM 5.3
CVE-2024-56332

Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, …

Fix: 13.5.8 / 14.2.21+
Fix from $1,600 2025-01-03
Linux Kernel MEDIUM 5.5
CVE-2022-49035

In the Linux kernel, the following vulnerability has been resolved: media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE I expect that the hardware wi…

Fix: 4.9.333 / 4.14.299+
Fix from $1,600 2025-01-02
Id Security HIGH 8.2
CVE-2024-53647

Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verificatio…

Fix: after 3.0
Fix from $1,950 2024-12-31
Linux Kernel MEDIUM 5.5
CVE-2024-56722

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix cpu stuck caused by printings during reset During reset, cmd to d…

Fix: 6.1.120 / 6.6.64+
Fix from $1,600 2024-12-29
Linux Kernel MEDIUM 5.5
CVE-2024-56584

In the Linux kernel, the following vulnerability has been resolved: io_uring/tctx: work around xa_store() allocation error issue syzbot triggered t…

Fix: 6.1.120 / 6.6.66+
Fix from $1,600 2024-12-27
Ipados HIGH 7.5
CVE-2024-54538

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1…

Fix: 2.1 / 11.1+
Fix from $1,950 2024-12-20
Db2 MEDIUM 6.5
CVE-2023-30443

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Mitigation only
Fix from $1,600 2024-12-19
Unclassified HIGH 7.5
CVE-2024-56319

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a den…

Patch available
Fix from $1,950 2024-12-18
Ipados MEDIUM 5.5
CVE-2024-54501

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2…

Fix: 2.2 / 11.2+
Fix from $1,600 2024-12-12
Ipados CRITICAL 9.8
CVE-2024-44241

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to …

Fix: 18.1+
Fix from $2,300 2024-12-12
Bitcoin Core MEDIUM 5.3
CVE-2024-55563

Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outc…

Fix: after 27.2
Fix from $1,600 2024-12-09
Db2 MEDIUM 6.5
CVE-2024-41762

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u…

Fix: after 11.5.9
Fix from $1,600 2024-12-07
Unclassified HIGH 7.5
CVE-2024-12254

Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain t…

Patch available
Fix from $1,950 2024-12-06
Django HIGH 7.5
CVE-2024-53907

An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter a…

Fix: 4.2.17 / 5.0.10+
Fix from $1,950 2024-12-06