Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Android MEDIUM 5.5
CVE-2024-43083

In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local den…

Patch available
Fix from $1,600 2024-11-13
Unclassified HIGH 7.5
CVE-2024-48989

A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of servic…

Mitigation only
Fix from $1,950 2024-11-13
Esp Idf HIGH 7.5
CVE-2024-51428

An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.

Mitigation only
Fix from $1,950 2024-11-07
Tomcat HIGH 7.5
CVE-2024-38286

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0…

Fix: 9.0.90 / 10.1.25+
Fix from $1,950 2024-11-07
Onos A1t HIGH 7.5
CVE-2024-48809

An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the ono…

No fix yet
Fix from $1,950 2024-11-04
Aero MEDIUM 6.5
CVE-2024-51557

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exp…

Fix: 1.1.7 / 120820241550+
Fix from $1,600 2024-11-04
Office Anywhere HIGH 7.5
CVE-2024-10599

A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects some unknown processing of the …

Fix: after 11.7
Fix from $1,950 2024-10-31
Wbr 6012 Firmware HIGH 7.5
CVE-2024-31152EPSS 18%

The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafte…

No fix yet
Fix from $1,950 2024-10-30
Chuanhuchatgpt HIGH 7.5
CVE-2024-7807

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker app…

Patch available
Fix from $1,950 2024-10-29
Firefox MEDIUM 5.3
CVE-2024-10468

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Fi…

Fix: 132.0+
Fix from $1,600 2024-10-29
Mattermost Server HIGH 7.5
CVE-2024-47401

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks w…

Fix: 9.5.10 / 9.10.3+
Fix from $1,950 2024-10-29
Unclassified CRITICAL 9.1
CVE-2024-38821

Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this …

Mitigation only
Fix from $2,300 2024-10-28
Quart HIGH 7.5
CVE-2024-49767

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a versi…

Fix: 0.19.7 / 3.0.6+
Fix from $1,950 2024-10-25
GitLab MEDIUM 6.5
CVE-2024-6826

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of …

Fix: 17.3.6 / 17.4.3+
Fix from $1,600 2024-10-24
Adaptive Security Appliance Software MEDIUM 5.3
CVE-2024-20526

A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a deni…

Mitigation only
Fix from $1,600 2024-10-23
Db2 MEDIUM 6.5
CVE-2024-31880

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configura…

Fix: after 11.5.9
Fix from $1,600 2024-10-23
Unclassified MEDIUM 5.3
CVE-2024-45526

An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credenti…

Mitigation only
Fix from $1,600 2024-10-22
Openshift Container Platform MEDIUM 6.5
CVE-2024-50311

A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnera…

Mitigation only
Fix from $1,600 2024-10-22
Libhtp HIGH 7.5
CVE-2024-45797

LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unbounded processing of HTTP reques…

Fix: 0.5.49+
Fix from $1,950 2024-10-16
Unclassified MEDIUM 6.6
CVE-2024-41128

Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, an…

Patch available
Fix from $1,600 2024-10-16
Unclassified HIGH 8.7
CVE-2024-47874

Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts…

Patch available
Fix from $1,950 2024-10-15
Jetty MEDIUM 6.5
CVE-2024-8184

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-o…

Fix: 9.4.56 / 10.0.24+
Fix from $1,600 2024-10-14
Jetty MEDIUM 6.5
CVE-2024-6762

Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.

Fix: 10.0.18 / 11.0.18+
Fix from $1,600 2024-10-14
Junos Os Evolved MEDIUM 6.5
CVE-2024-47509

An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved…

Fix: 21.4+
Fix from $1,600 2024-10-11
Junos Os Evolved MEDIUM 6.5
CVE-2024-47505

An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved…

Fix: 21.4+
Fix from $1,600 2024-10-11
Junos Os Evolved MEDIUM 6.5
CVE-2024-47508

An Allocation of Resources Without Limits or Throttling vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved…

Fix: 21.2+
Fix from $1,600 2024-10-11
Junos Os Evolved HIGH 7.5
CVE-2024-47502

An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, n…

Fix: 21.4+
Fix from $1,950 2024-10-11
Bitcoin Core HIGH 7.5
CVE-2024-35202

Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transa…

Fix: 25.0+
Fix from $1,950 2024-10-10
Windows Server 2012 HIGH 7.5
CVE-2024-43567

Windows Hyper-V Denial of Service Vulnerability

Fix: 10.0.14393.7428 / 10.0.17763.6414+
Fix from $1,950 2024-10-08
Unclassified MEDIUM 6.2
CVE-2024-47969

Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Mitigation only
Fix from $1,600 2024-10-07