Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Unclassified HIGH 7.5
CVE-2024-53857

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by provi…

Mitigation only
Fix from $1,950 2024-12-05
Aspect Ent 2 Firmware HIGH 7.5
CVE-2024-48843

Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3…

Fix: 3.08.03+
Fix from $1,950 2024-12-05
Aspect Ent 2 Firmware MEDIUM 6.5
CVE-2024-48844

Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3…

Fix: 3.08.03+
Fix from $1,600 2024-12-05
Aspect Ent 2 Firmware HIGH 7.5
CVE-2024-11316

Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products: ABB ASPECT - Enterprise…

Fix: 3.08.03+
Fix from $1,950 2024-12-05
Unclassified HIGH 7.5
CVE-2024-48080

An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier indicates that exploitation ca…

Mitigation only
Fix from $1,950 2024-12-03
Synapse HIGH 7.5
CVE-2024-52805

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increa…

Fix: 1.120.1+
Fix from $1,950 2024-12-03
Synapse HIGH 7.5
CVE-2024-37302

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary c…

Fix: 1.106.0+
Fix from $1,950 2024-12-03
Unclassified HIGH 7.5
CVE-2024-53981

python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of …

Patch available
Fix from $1,950 2024-12-02
Rizin HIGH 7.5
CVE-2024-31669

rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimate_slide.

Fix: 0.6.3+
Fix from $1,950 2024-12-02
Db2 MEDIUM 5.3
CVE-2024-41761

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u…

Mitigation only
Fix from $1,600 2024-11-23
Tornado HIGH 7.5
CVE-2024-52804

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2…

Fix: 6.4.2+
Fix from $1,950 2024-11-22
Opencast HIGH 7.5
CVE-2024-52797

Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch…

Fix: 13.10 / 14.3+
Fix from $1,950 2024-11-21
Litestar HIGH 7.5
CVE-2024-52581

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parser shipped with litestar expec…

Fix: 2.13.0+
Fix from $1,950 2024-11-20
Esoft Planner HIGH 7.5
CVE-2024-48530

An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a …

No fix yet
Fix from $1,950 2024-11-20
Unclassified MEDIUM 5.3
CVE-2024-52796

Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions p…

Mitigation only
Fix from $1,600 2024-11-20
Unclassified HIGH 7.5
CVE-2024-21539

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitiza…

Patch available
Fix from $1,950 2024-11-19
Linux Kernel MEDIUM 5.5
CVE-2024-50285

In the Linux kernel, the following vulnerability has been resolved: ksmbd: check outstanding simultaneous SMB operations If Client send simultaneou…

Fix: 6.6.61 / 6.11.8+
Fix from $1,600 2024-11-19
Linux Kernel MEDIUM 5.5
CVE-2024-50271

In the Linux kernel, the following vulnerability has been resolved: signal: restore the override_rlimit logic Prior to commit d64696905554 ("Reimpl…

Fix: 6.1.117 / 6.6.61+
Fix from $1,600 2024-11-19
Unclassified HIGH 7.4
CVE-2021-1285

Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthen…

Mitigation only
Fix from $1,950 2024-11-18
Bitcoin Core HIGH 7.5
CVE-2019-25220

Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Ch…

Fix: 24.0.1+
Fix from $1,950 2024-11-18
Bitcoin Core MEDIUM 5.3
CVE-2024-52913

In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are m…

Fix: 0.21.0+
Fix from $1,600 2024-11-18
Bitcoin Core HIGH 7.5
CVE-2024-52914

In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.

Fix: 0.18.0+
Fix from $1,950 2024-11-18
Bitcoin Core HIGH 7.5
CVE-2024-52915

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.

Fix: 0.20.0+
Fix from $1,950 2024-11-18
Bitcoin Core HIGH 7.5
CVE-2024-52916

Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

Fix: 0.15.0+
Fix from $1,950 2024-11-18
Bitcoin Core MEDIUM 6.5
CVE-2024-52917

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large…

Fix: 22.0+
Fix from $1,600 2024-11-18
Unclassified MEDIUM 6.5
CVE-2024-52918

Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 …

Mitigation only
Fix from $1,600 2024-11-18
Bitcoin Core HIGH 7.5
CVE-2024-52920

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

Fix: 0.20.0+
Fix from $1,950 2024-11-18
Lunary HIGH 7.5
CVE-2024-3760

In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers…

Fix: 1.2.8+
Fix from $1,950 2024-11-14
Zenml MEDIUM 5.4
CVE-2024-4311

zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can …

Patch available
Fix from $1,600 2024-11-14
Unclassified HIGH 7.5
CVE-2024-50955

An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a crafted T…

Mitigation only
Fix from $1,950 2024-11-13