Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Rexml MEDIUM 5.3
CVE-2024-35176

REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `<`s in an att…

Fix: 3.2.7+
Fix from $1,600 2024-05-16
Unclassified MEDIUM 5.3
CVE-2024-35185

Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack vi…

Patch available
Fix from $1,600 2024-05-16
TYPO3 MEDIUM 5.3
CVE-2024-34358

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS…

Fix: 9.5.48 / 10.4.45+
Fix from $1,600 2024-05-14
Unclassified MEDIUM 6.5
CVE-2024-33495

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT278…

Mitigation only
Fix from $1,600 2024-05-14
Powerscale Onefs MEDIUM 5.5
CVE-2024-25969

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthen…

Fix: 9.4.0.18 / 9.5.0.8+
Fix from $1,600 2024-05-14
GitLab MEDIUM 6.5
CVE-2024-4539

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and sta…

Fix: 16.9.7 / 16.10.5+
Fix from $1,600 2024-05-14
Unclassified MEDIUM 6.8
CVE-2024-32874

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retriev…

Patch available
Fix from $1,600 2024-05-14
GitLab MEDIUM 6.5
CVE-2024-2454EPSS 33%

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and st…

Fix: 16.9.7 / 16.10.5+
Fix from $1,600 2024-05-14
Ipados MEDIUM 5.5
CVE-2024-27804

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, w…

Fix: 1.3 / 10.5+
Fix from $1,600 2024-05-14
Android MEDIUM 5.5
CVE-2024-0026

In multiple functions of SnoozeHelper.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local den…

Patch available
Fix from $1,600 2024-05-07
Android MEDIUM 5.5
CVE-2024-0027

In multiple functions of SnoozeHelper.java, there is a possible way to cause a boot loop due to resource exhaustion. This could lead to local denial …

Patch available
Fix from $1,600 2024-05-07
Suricata HIGH 7.5
CVE-2024-32663

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a sm…

Fix: 6.0.19 / 7.0.5+
Fix from $1,950 2024-05-07
Fedora HIGH 7.5
CVE-2024-4140

An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME mes…

Fix: 1.954+
Fix from $1,950 2024-05-02
Linux Kernel MEDIUM 5.5
CVE-2024-27013

In the Linux kernel, the following vulnerability has been resolved: tun: limit printing rate when illegal packet received by tun dev vhost_worker w…

Fix: 4.19.313 / 5.4.275+
Fix from $1,600 2024-05-01
Unclassified HIGH 7.5
CVE-2024-34046

The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_C…

Mitigation only
Fix from $1,950 2024-04-30
Mattermost Server MEDIUM 6.5
CVE-2024-4183

Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, whic…

Fix: 8.1.12 / 9.4.5+
Fix from $1,600 2024-04-26
Mattermost Server MEDIUM 6.5
CVE-2024-22091

Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user i…

Fix: 8.1.12 / 9.5.3+
Fix from $1,600 2024-04-26
Websphere Application Server HIGH 7.5
CVE-2024-25026

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 are vulnerable to a denial of servic…

Fix: after 24.0.0.4
Fix from $1,950 2024-04-25
Fedora HIGH 7.5
CVE-2024-32660

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending i…

Fix: 2.11.7 / 3.5.1+
Fix from $1,950 2024-04-23
Fedora MEDIUM 6.5
CVE-2024-31208

Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can di…

Fix: 1.105.1+
Fix from $1,600 2024-04-23
Mealie MEDIUM 6.5
CVE-2024-31994

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. Mealie…

Fix: 1.4.0+
Fix from $1,600 2024-04-19
Mealie MEDIUM 6.5
CVE-2024-31992

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a requ…

Fix: 1.4.0+
Fix from $1,600 2024-04-19
Linux Kernel MEDIUM 6.0
CVE-2024-26894

In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() After unre…

Fix: 4.19.311 / 5.4.273+
Fix from $1,600 2024-04-17
Unclassified HIGH 7.7
CVE-2024-31446

OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. A user can use OpenComputers to get a Computer thread stuck…

Patch available
Fix from $1,950 2024-04-16
Lunary MEDIUM 5.3
CVE-2024-1666

In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerability stems from the lack of ser…

Fix: 1.2.7+
Fix from $1,600 2024-04-16
Imagesharp MEDIUM 6.5
CVE-2024-32035

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to ex…

Fix: 2.1.8 / 3.1.4+
Fix from $1,600 2024-04-15
Cosign HIGH 7.5
CVE-2024-29903

Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, maliciously-crafted software artifacts can cause d…

Fix: 2.2.4+
Fix from $1,950 2024-04-10
Cosign MEDIUM 5.9
CVE-2024-29902

Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a malicious attachment can cau…

Fix: 2.2.4+
Fix from $1,600 2024-04-10
Linux Kernel MEDIUM 5.5
CVE-2021-47182

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix scsi_mode_sense() buffer length handling Several problems exist…

Fix: 5.15.5+
Fix from $1,600 2024-04-10
Pan Os HIGH 7.5
CVE-2024-3382

A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that even…

Fix: 10.2.7 / 11.0.4+
Fix from $1,950 2024-04-10