Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Linux Kernel MEDIUM 5.5
CVE-2024-42241

In the Linux kernel, the following vulnerability has been resolved: mm/shmem: disable PMD-sized page cache if needed For shmem files, it's possible…

Fix: 6.6.41 / 6.9.10+
Fix from $1,600 2024-08-07
Nvr4104 4ks2\/l Firmware HIGH 7.5
CVE-2024-39944

A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the…

Fix: 4.003.0000000.1.r.240515+
Fix from $1,950 2024-07-31
Linux Kernel MEDIUM 5.5
CVE-2024-42145

In the Linux kernel, the following vulnerability has been resolved: IB/core: Implement a limit on UMAD receive List The existing behavior of ib_uma…

Fix: 4.19.318 / 5.4.280+
Fix from $1,600 2024-07-30
Linux Kernel MEDIUM 5.5
CVE-2024-42082

In the Linux kernel, the following vulnerability has been resolved: xdp: Remove WARN() from __xdp_reg_mem_model() syzkaller reports a warning in __…

Fix: 4.18 / 5.10.221+
Fix from $1,600 2024-07-29
Unclassified HIGH 7.5
CVE-2024-0760

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server…

Mitigation only
Fix from $1,950 2024-07-23
Unclassified HIGH 7.5
CVE-2024-1737

Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded p…

Mitigation only
Fix from $1,950 2024-07-23
Unclassified HIGH 7.5
CVE-2024-1975

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in ca…

Mitigation only
Fix from $1,950 2024-07-23
Imagesharp HIGH 7.5
CVE-2024-41132

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to ex…

Fix: 2.1.9 / 3.1.5+
Fix from $1,950 2024-07-22
Insightvm MEDIUM 5.3
CVE-2024-6504

Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM C…

Fix: 6.6.261+
Fix from $1,600 2024-07-18
Linux Kernel MEDIUM 5.5
CVE-2024-41009

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overrunning reservations in ringbuf The BPF ring buffer internally is …

Fix: 6.1.97 / 6.6.37+
Fix from $1,600 2024-07-17
Suricata HIGH 7.5
CVE-2024-38534

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead…

Fix: 7.0.6+
Fix from $1,950 2024-07-11
Suricata HIGH 7.5
CVE-2024-38535

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory …

Fix: 6.0.20 / 7.0.6+
Fix from $1,950 2024-07-11
Chuanhuchatgpt CRITICAL 9.1
CVE-2024-6037EPSS 11%

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, includin…

Patch available
Fix from $2,300 2024-07-10
Android MEDIUM 5.5
CVE-2024-31314

In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of serv…

Patch available
Fix from $1,600 2024-07-09
Firefox MEDIUM 6.3
CVE-2024-6600

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in…

Fix: 115.13 / 128.0+
Fix from $1,600 2024-07-09
Business Hub MEDIUM 6.5
CVE-2024-6598

A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It allows an authenticated attack…

Fix: 1.10.2+
Fix from $1,600 2024-07-09
Unclassified HIGH 7.5
CVE-2024-33862

A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow remote attackers to exhaust …

Mitigation only
Fix from $1,950 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39472

In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the legacy h_size fixup Commit a70f…

Fix: after 6.9.3
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39474

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL commi…

Fix: 5.17 / 6.1.95+
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39477

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon ENOMEM sysbot reported a splat…

Fix: 6.9.5+
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39478

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length …

Fix: 6.9.5+
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39482

In the Linux kernel, the following vulnerability has been resolved: bcache: fix variable length array abuse in btree_iter btree_iter is used in two…

Fix: 5.10.221 / 5.15.162+
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39484

In the Linux kernel, the following vulnerability has been resolved: mmc: davinci: Don't strip remove function when driver is builtin Using __exit f…

Fix: 2.6.33 / 5.10.221+
Fix from $1,600 2024-07-05
Mesbook HIGH 7.5
CVE-2024-6427

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to…

Mitigation only
Fix from $1,950 2024-07-03
Unclassified HIGH 7.5
CVE-2024-37298

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of typ…

Patch available
Fix from $1,950 2024-07-01
Unclassified HIGH 7.5
CVE-2024-34703

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of …

Patch available
Fix from $1,950 2024-06-30
Unclassified HIGH 7.5
CVE-2024-38528

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing limit for accepted NTS-KE conne…

Mitigation only
Fix from $1,950 2024-06-28
Mq HIGH 7.5
CVE-2024-35116

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes. …

Fix: 9.0.0.26 / 9.1.0.22+
Fix from $1,950 2024-06-28
Mq HIGH 7.5
CVE-2024-31919

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error proce…

Mitigation only
Fix from $1,950 2024-06-28
Unclassified MEDIUM 6.5
CVE-2024-37681

An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a denial of ser…

No fix yet
Fix from $1,600 2024-06-24