Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Linux Kernel MEDIUM 5.5
CVE-2024-39474

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL commi…

Fix: 5.17 / 6.1.95+
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39477

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon ENOMEM sysbot reported a splat…

Fix: 6.9.5+
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39478

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length …

Fix: 6.9.5+
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39482

In the Linux kernel, the following vulnerability has been resolved: bcache: fix variable length array abuse in btree_iter btree_iter is used in two…

Fix: 5.10.221 / 5.15.162+
Fix from $1,600 2024-07-05
Linux Kernel MEDIUM 5.5
CVE-2024-39484

In the Linux kernel, the following vulnerability has been resolved: mmc: davinci: Don't strip remove function when driver is builtin Using __exit f…

Fix: 2.6.33 / 5.10.221+
Fix from $1,600 2024-07-05
Mesbook HIGH 7.5
CVE-2024-6427

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to…

Mitigation only
Fix from $1,950 2024-07-03
Unclassified HIGH 7.5
CVE-2024-37298

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of typ…

Patch available
Fix from $1,950 2024-07-01
Unclassified HIGH 7.5
CVE-2024-34703

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of …

Patch available
Fix from $1,950 2024-06-30
Unclassified HIGH 7.5
CVE-2024-38528

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing limit for accepted NTS-KE conne…

Mitigation only
Fix from $1,950 2024-06-28
Mq HIGH 7.5
CVE-2024-35116

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes. …

Fix: 9.0.0.26 / 9.1.0.22+
Fix from $1,950 2024-06-28
Mq HIGH 7.5
CVE-2024-31919

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error proce…

Mitigation only
Fix from $1,950 2024-06-28
Unclassified MEDIUM 6.5
CVE-2024-37681

An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a denial of ser…

No fix yet
Fix from $1,600 2024-06-24
Linux Kernel HIGH 7.8
CVE-2024-34027

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem loc…

Fix: 5.10.219 / 5.15.161+
Fix from $1,950 2024-06-24
Anythingllm MEDIUM 6.5
CVE-2024-5208

An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows atta…

Fix: 1.0.0+
Fix from $1,600 2024-06-19
Cratedb MEDIUM 5.3
CVE-2024-37309

CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) pe…

Fix: 5.7.2+
Fix from $1,600 2024-06-13
Db2 MEDIUM 6.5
CVE-2024-31881

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…

Mitigation only
Fix from $1,600 2024-06-12
Db2 MEDIUM 6.5
CVE-2024-28762

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…

Mitigation only
Fix from $1,600 2024-06-12
Cyrus Imap MEDIUM 6.5
CVE-2024-34055

Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in …

Fix: 3.8.3+
Fix from $1,600 2024-06-05
Ubuntu Linux MEDIUM 5.5
CVE-2022-28656

is_closing_session() allows users to consume RAM in the Apport process

Fix: 2.21.0+
Fix from $1,600 2024-06-04
Ubuntu Linux MEDIUM 5.5
CVE-2022-28654

is_closing_session() allows users to fill up apport.log

Fix: 2.21.0+
Fix from $1,600 2024-06-04
Ubuntu Linux HIGH 7.1
CVE-2022-28655

is_closing_session() allows users to create arbitrary tcp dbus connections

Fix: 2.21.0+
Fix from $1,950 2024-06-04
Pimcore HIGH 7.5
CVE-2024-32871

Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. B…

Fix: 11.2.4+
Fix from $1,950 2024-06-04
Teamcity HIGH 7.5
CVE-2024-36378

In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens

Fix: 2024.03.2+
Fix from $1,950 2024-05-29
Unclassified MEDIUM 5.3
CVE-2024-35238

Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerable to a denial-of-service (Do…

Patch available
Fix from $1,600 2024-05-27
Unclassified HIGH 8.6
CVE-2024-35231

rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vu…

Patch available
Fix from $1,950 2024-05-27
Linux Kernel HIGH 7.8
CVE-2021-47551

In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again In …

Fix: 5.10.84 / 5.15.7+
Fix from $1,950 2024-05-24
GitLab MEDIUM 6.5
CVE-2024-2874

An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. A runner re…

Fix: 16.10.6 / 16.11.3+
Fix from $1,600 2024-05-23
Openlitespeed MEDIUM 5.3
CVE-2024-31617

OpenLiteSpeed before 1.8.1 mishandles chunked encoding.

Fix: 1.8.1+
Fix from $1,600 2024-05-22
Linux Kernel MEDIUM 5.5
CVE-2021-47374

In the Linux kernel, the following vulnerability has been resolved: dma-debug: prevent an error message from causing runtime problems For some driv…

Fix: 5.14.9+
Fix from $1,600 2024-05-21
Linux Kernel HIGH 8.8
CVE-2024-35969

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr Although ipv…

Fix: 4.19.313 / 5.4.275+
Fix from $1,950 2024-05-20