Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Faktory HIGH 7.5
CVE-2023-37279

Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer from denial of service …

Fix: 1.8.0+
Fix from $1,950 2023-09-20
Ekorccp Firmware HIGH 7.5
CVE-2022-47562

Vulnerability in the RCPbind service running on UDP port (111), allowing a remote attacker to create a denial of service (DoS) condition.

Mitigation only
Fix from $1,950 2023-09-20
Rancher Rke2 HIGH 7.5
CVE-2023-32186

A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor p…

Fix: 1.24.17 / 1.25.13+
Fix from $1,950 2023-09-19
K3s HIGH 7.5
CVE-2023-32187

An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supervisor p…

Fix: 1.24.17 / 1.25.13+
Fix from $1,950 2023-09-18
Discourse MEDIUM 6.5
CVE-2023-40588

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passe…

Fix: 3.1.1+
Fix from $1,600 2023-09-15
Discourse MEDIUM 6.5
CVE-2023-41042

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passe…

Fix: 3.1.1+
Fix from $1,600 2023-09-15
Discourse MEDIUM 6.5
CVE-2023-41043

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passe…

Fix: 3.1.1+
Fix from $1,600 2023-09-15
Discourse MEDIUM 6.5
CVE-2023-38706

Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passe…

Fix: 3.1.0+
Fix from $1,600 2023-09-15
Freeswitch MEDIUM 6.5
CVE-2023-40019

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…

Fix: 1.10.10+
Fix from $1,600 2023-09-15
Strapi CRITICAL 9.8
CVE-2023-38507

Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's adm…

Fix: 4.12.1+
Fix from $2,300 2023-09-15
Curl HIGH 7.5
CVE-2023-38039EPSS 62%

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl d…

Fix: 8.3.0 / 10.0.17763.5122+
Fix from $1,950 2023-09-15
Firefox MEDIUM 6.5
CVE-2023-4578

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the fun…

Fix: 115.2 / 117.0+
Fix from $1,600 2023-09-11
Go HIGH 7.5
CVE-2023-39322

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection …

Fix: 1.21.1+
Fix from $1,950 2023-09-08
GitLab HIGH 7.5
CVE-2023-4647

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all ve…

Fix: 16.1.5 / 16.2.5+
Fix from $1,950 2023-09-01
Snap Pac S1 Firmware HIGH 7.5
CVE-2023-40709

An adversary could crash the entire device by sending a large quantity of ICMP requests if the controller has the built-in web server enabled but doe…

Mitigation only
Fix from $1,950 2023-08-24
Snap Pac S1 Firmware HIGH 7.5
CVE-2023-40710

An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests if the controller has the bu…

Mitigation only
Fix from $1,950 2023-08-24
Fedora MEDIUM 5.5
CVE-2022-48064

GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_a…

Fix: 2.40+
Fix from $1,600 2023-08-22
Grpc HIGH 7.5
CVE-2023-33953

gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional…

Fix: 1.53.2 / 1.54.3+
Fix from $1,950 2023-08-09
Go Libp2p HIGH 7.5
CVE-2023-39533

go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys…

Fix: 0.27.8 / 0.28.2+
Fix from $1,950 2023-08-08
Ruggedcom Ros HIGH 7.5
CVE-2023-39269

A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCO…

Fix: 4.3.8+
Fix from $1,950 2023-08-08
Parasolid MEDIUM 5.5
CVE-2023-38532

A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All v…

Fix: 14.1.0.11 / 14.2.0.6+
Fix from $1,600 2023-08-08
Rdiffweb MEDIUM 6.5
CVE-2023-4138

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.

Fix: 2.8.0+
Fix from $1,600 2023-08-03
Image MEDIUM 6.5
CVE-2023-29408

The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (bot…

Fix: 0.10.0+
Fix from $1,600 2023-08-02
Ngsurvey HIGH 7.5
CVE-2022-46485

Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Co…

Fix: after 2.4.28
Fix from $1,950 2023-08-02
GitLab HIGH 7.5
CVE-2023-4011

An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumptio…

Fix: 16.2.2+
Fix from $1,950 2023-08-02
Firefox MEDIUM 5.3
CVE-2023-4046

In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a po…

Fix: 102.14 / 115.1+
Fix from $1,600 2023-08-01
Discourse MEDIUM 6.5
CVE-2023-38498

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passe…

Fix: 3.0.6+
Fix from $1,600 2023-07-28
Discourse HIGH 7.5
CVE-2023-38684

Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passe…

Fix: 3.0.6+
Fix from $1,950 2023-07-28
Kirby HIGH 7.5
CVE-2023-38492

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with…

Fix: 3.5.8.3 / 3.6.6.3+
Fix from $1,950 2023-07-27
Automation Runtime MEDIUM 5.9
CVE-2023-3242

Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based…

Mitigation only
Fix from $1,600 2023-07-26