Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Wyse Management Suite MEDIUM 6.5
CVE-2023-32481

Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood the configured SMTP …

Fix: 4.0+
Fix from $1,600 2023-07-20
Cp3n 6505417 Firmware HIGH 7.5
CVE-2023-38405

On Crestron 3-Series Control Systems before 1.8001.0187, crafting and sending a specific BACnet packet can cause a crash.

Fix: 1.8001.0187+
Fix from $1,950 2023-07-17
Simatic Mv540 H Firmware HIGH 7.5
CVE-2023-36521

A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3.4), SIMATIC MV540 S (All versions < V3.3.4), SIMATIC MV550 H (All version…

Fix: 3.3.4+
Fix from $1,950 2023-07-11
Wallabag MEDIUM 6.5
CVE-2023-3566

A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the f…

No fix yet
Fix from $1,600 2023-07-10
Cloud Pak For Data HIGH 7.5
CVE-2023-27540

IBM Watson CP4D Data Stores 4.6.0 does not properly allocate resources without limits or throttling which could allow a remote attacker with informat…

Mitigation only
Fix from $1,950 2023-07-10
Mastodon HIGH 7.5
CVE-2023-36461

Mastodon is a free, open-source social network server based on ActivityPub. When performing outgoing HTTP queries, Mastodon sets a timeout on individ…

Fix: 3.5.9 / 4.0.5+
Fix from $1,950 2023-07-06
Cometbft MEDIUM 5.3
CVE-2023-34450

CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many machines. An internal modific…

Fix: 0.34.29 / 0.37.2+
Fix from $1,600 2023-07-03
Products.cmfcore HIGH 7.5
CVE-2023-36814

Products.CMFCore are the key framework services for the Zope Content Management Framework (CMF). The use of Python's marshal module to handle uncheck…

Fix: 3.2+
Fix from $1,950 2023-07-03
Unified Communications Manager Im And Presence Service HIGH 7.5
CVE-2023-20108

A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could a…

Mitigation only
Fix from $1,950 2023-06-28
Ipados MEDIUM 5.5
CVE-2023-32385

A denial-of-service issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, macOS Ventura 13.4. Opening a…

Fix: 13.4 / 16.5+
Fix from $1,600 2023-06-23
Netty MEDIUM 6.5
CVE-2023-34462

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients…

Fix: 4.1.94+
Fix from $1,600 2023-06-22
Tl Wr940n Firmware HIGH 7.7
CVE-2023-36357

An issue in the /userRpm/LocalManageControlRpm component of TP-Link TL-WR940N V2/V4/V6, TL-WR841N V8/V10, and TL-WR941ND V5 allows attackers to cause…

No fix yet
Fix from $1,950 2023-06-22
Monetdb HIGH 7.5
CVE-2023-36369

An issue in the list_append component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL st…

Patch available
Fix from $1,950 2023-06-22
Monetdb HIGH 7.5
CVE-2023-36370

An issue in the gc_col component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL stateme…

Patch available
Fix from $1,950 2023-06-22
Monetdb HIGH 7.5
CVE-2023-36371

An issue in the GDKfree component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statem…

Patch available
Fix from $1,950 2023-06-22
Monetdb HIGH 7.5
CVE-2023-36365

An issue in the sql_trans_copy_key component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted…

Patch available
Fix from $1,950 2023-06-22
Monetdb HIGH 7.5
CVE-2023-36366

An issue in the log_create_delta component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause Denial of Service (DoS) via crafted SQL…

Patch available
Fix from $1,950 2023-06-22
Monetdb HIGH 7.5
CVE-2023-36367

An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statem…

Patch available
Fix from $1,950 2023-06-22
Monetdb HIGH 7.5
CVE-2023-36368

An issue in the cs_bind_ubat component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL s…

Patch available
Fix from $1,950 2023-06-22
Debian Linux HIGH 7.5
CVE-2023-2828

Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent…

Fix: after 9.19.13
Fix from $1,950 2023-06-21
Emui HIGH 7.5
CVE-2023-34166

Vulnerability of system restart triggered by abnormal callbacks passed to APIs.Successful exploitation of this vulnerability may cause the system to …

No fix yet
Fix from $1,950 2023-06-19
Emui HIGH 7.5
CVE-2022-48498

Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,950 2023-06-19
Hp Ux MEDIUM 5.5
CVE-2023-30903

HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6.

Fix: after 11.31
Fix from $1,600 2023-06-16
Android HIGH 7.5
CVE-2023-21144

In doInBackground of NotificationContentInflater.java, there is a possible temporary denial or service due to long running operations. This could lea…

Patch available
Fix from $1,950 2023-06-15
Snappy Java HIGH 7.5
CVE-2023-34455

snappy-java is a fast compressor/decompressor for Java. Due to use of an unchecked chunk length, an unrecoverable fatal error can occur in versions p…

Fix: 1.1.10.1+
Fix from $1,950 2023-06-15
Struts MEDIUM 6.5
CVE-2023-34149EPSS 5%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro…

Fix: 2.5.31 / 6.1.2.1+
Fix from $1,600 2023-06-14
Struts HIGH 7.5
CVE-2023-34396EPSS 6%

Allocation of Resources Without Limits or Throttling vulnerability in Apache Software Foundation Apache Struts.This issue affects Apache Struts: thro…

Fix: 2.5.31 / 6.1.2.1+
Fix from $1,950 2023-06-14
Crossx MEDIUM 5.5
CVE-2023-29767

An issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files.

No fix yet
Fix from $1,600 2023-06-09
GitLab HIGH 7.5
CVE-2023-0121

A denial of service issue was discovered in GitLab CE/EE affecting all versions starting from 13.2.4 before 15.10.8, all versions starting from 15.11…

Fix: 15.10.8 / 15.11.7+
Fix from $1,950 2023-06-07
Openshift Api For Data Protection MEDIUM 6.5
CVE-2023-2253

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records retu…

Mitigation only
Fix from $1,600 2023-06-06