Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Bind HIGH 7.5
CVE-2023-6516

To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods…

Fix: after 9.16.45
Fix from $1,950 2024-02-13
Hacker Hotel Badge 2024 MEDIUM 6.5
CVE-2024-21875

Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team Hacker Hotel Badge 2024 on ris…

Fix: after 0.1.3
Fix from $1,600 2024-02-11
Nimbus Jose\+jwt HIGH 7.5
CVE-2023-52428

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka i…

Fix: 9.37.2+
Fix from $1,950 2024-02-11
Opendds HIGH 7.5
CVE-2023-52427

In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_samples. NOTE: the vendor's positio…

Fix: after 3.27
Fix from $1,950 2024-02-11
GitLab MEDIUM 6.5
CVE-2024-1066

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which al…

Fix: 16.6.7 / 16.7.5+
Fix from $1,600 2024-02-07
Digital Experience Platform MEDIUM 6.5
CVE-2024-25143

The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 b…

Fix: 7.2 / 7.2.0+
Fix from $1,600 2024-02-07
Bref MEDIUM 6.5
CVE-2024-24752

Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, th…

Fix: 2.1.13+
Fix from $1,600 2024-02-01
Spbu Se Site MEDIUM 5.7
CVE-2024-23826

spbu_se_site is the website of the Department of System Programming of St. Petersburg State University. Before 2024.01.29, when uploading an avatar i…

Fix: 2024.01.29+
Fix from $1,600 2024-01-29
Openfga MEDIUM 6.5
CVE-2024-23820

OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on…

Fix: 1.4.3+
Fix from $1,600 2024-01-26
Tinydtls CRITICAL 9.8
CVE-2021-42142

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vuln…

Fix: after 2018-08-30
Fix from $2,300 2024-01-23
Db2 MEDIUM 6.5
CVE-2023-47746

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to c…

Fix: after 11.5.9
Fix from $1,600 2024-01-22
Superb 3 Firmware MEDIUM 5.5
CVE-2023-28899

By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service of ot…

Mitigation only
Fix from $1,600 2024-01-12
Junos Os Evolved HIGH 7.5
CVE-2024-21604

An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, n…

Mitigation only
Fix from $1,950 2024-01-12
Fortipam MEDIUM 6.5
CVE-2023-37934

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perf…

Fix: 1.1.0+
Fix from $1,600 2024-01-10
Openshift Container Platform HIGH 7.5
CVE-2023-6476

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get a…

Mitigation only
Fix from $1,950 2024-01-09
Encodedid\ HIGH 7.5
CVE-2024-0241

encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacke…

Fix: 1.0.0+
Fix from $1,950 2024-01-04
Ion HIGH 7.5
CVE-2024-21634

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for a…

Fix: 1.10.5+
Fix from $1,950 2024-01-03
Cubefs MEDIUM 6.5
CVE-2023-46738

CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that c…

Fix: 3.3.1+
Fix from $1,600 2024-01-03
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-3171

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources…

Mitigation only
Fix from $1,950 2023-12-27
Grackle HIGH 7.5
CVE-2023-50730

Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification requires that GraphQL fragments must…

Fix: 0.18.0+
Fix from $1,950 2023-12-22
M Files Server MEDIUM 6.5
CVE-2023-6910

A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust serve…

Fix: 23.12.13195.0+
Fix from $1,600 2023-12-20
Keycloak HIGH 7.7
CVE-2023-6563

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline toke…

Fix: 21.0.0+
Fix from $1,950 2023-12-14
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-5379

A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error…

Mitigation only
Fix from $1,950 2023-12-12
H2o HIGH 7.5
CVE-2023-50247

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The QUIC stack (quicly), as used by H2O up to commit 43f86e5 (in version 2.3.0-be…

Fix: after 2.2.6
Fix from $1,950 2023-12-12
Zammad HIGH 7.5
CVE-2023-50455

An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many…

Mitigation only
Fix from $1,950 2023-12-10
Vault HIGH 7.5
CVE-2023-6337

HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large…

Fix: 1.13.12 / 1.14.8+
Fix from $1,950 2023-12-08
Nae55 Firmware HIGH 7.5
CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC e…

Fix: 12.0.4+
Fix from $1,950 2023-12-07
Availability Booking Calendar HIGH 7.5
CVE-2023-48831

A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

No fix yet
Fix from $1,950 2023-12-07
GitLab MEDIUM 6.5
CVE-2023-4912

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all…

Fix: 16.4.3 / 16.5.3+
Fix from $1,600 2023-12-01
Sel 451 Firmware MEDIUM 6.5
CVE-2023-34389

An allocation of resources without limits or throttling vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authent…

Mitigation only
Fix from $1,600 2023-11-30