Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Jetty MEDIUM 5.3
CVE-2023-26048

Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) th…

Fix: 9.4.51 / 10.0.14+
Fix from $1,600 2023-04-18
Appid Service Sigpack MEDIUM 5.3
CVE-2023-28968

An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application…

Fix: 1.550.2-31 / 5.7.0-47+
Fix from $1,600 2023-04-17
GitLab HIGH 7.5
CVE-2018-15472

An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter …

Fix: 11.1.7 / 11.2.4+
Fix from $1,950 2023-04-15
Poweramp HIGH 7.5
CVE-2023-27643

An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue …

No fix yet
Fix from $1,950 2023-04-14
Who HIGH 7.5
CVE-2023-27653

An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a denial of service via the SharedPreference files.

No fix yet
Fix from $1,950 2023-04-14
Tikv HIGH 7.5
CVE-2023-30636

TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for "not leader") upon an attempt to start a…

No fix yet
Fix from $1,950 2023-04-13
Bento4 MEDIUM 5.5
CVE-2023-29573

Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.

No fix yet
Fix from $1,600 2023-04-13
Pe8108 Firmware MEDIUM 5.3
CVE-2023-25414

Aten PE8108 2.4.232 is vulnerable to denial of service (DOS).

No fix yet
Fix from $1,600 2023-04-11
H2 HIGH 7.5
CVE-2023-26964

An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the m…

No fix yet
Fix from $1,950 2023-04-11
Simatic Cp 1242 7 V2 Firmware HIGH 7.5
CVE-2022-43768

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (Al…

Mitigation only
Fix from $1,950 2023-04-11
Super Security HIGH 7.5
CVE-2023-27191

An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files.

No fix yet
Fix from $1,950 2023-04-11
Go HIGH 7.5
CVE-2023-24536

Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems fro…

Fix: 1.19.8 / 1.20.3+
Fix from $1,950 2023-04-06
M Files Server MEDIUM 6.5
CVE-2023-0382

User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.

Fix: 23.4.12528.1+
Fix from $1,600 2023-04-05
Envoy MEDIUM 6.5
CVE-2023-27492

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, …

Fix: 1.22.9 / 1.23.6+
Fix from $1,600 2023-04-04
Emui HIGH 7.5
CVE-2022-48357

Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the ker…

No fix yet
Fix from $1,950 2023-03-27
Bebop Firmware MEDIUM 5.9
CVE-2022-46416

Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, th…

Mitigation only
Fix from $1,600 2023-03-27
Graphql Java HIGH 7.5
CVE-2023-28867

In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20…

Fix: 17.5 / 18.4+
Fix from $1,950 2023-03-27
Fedora MEDIUM 6.3
CVE-2023-1544

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a…

Fix: after 7.2.0
Fix from $1,600 2023-03-23
Ios Xe MEDIUM 6.5
CVE-2023-20067

A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticate…

Mitigation only
Fix from $1,600 2023-03-23
Saml HIGH 7.5
CVE-2023-28119

The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, the package's use of `flate.Ne…

Patch available
Fix from $1,950 2023-03-22
Debian Linux HIGH 8.6
CVE-2022-42333

x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c…

Fix: after 4.17.0
Fix from $1,950 2023-03-21
Debian Linux MEDIUM 6.5
CVE-2022-42334

x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c…

Fix: after 4.17.0
Fix from $1,600 2023-03-21
Jackson Databind HIGH 7.5
CVE-2021-46877

jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usag…

Fix: 2.12.6+
Fix from $1,950 2023-03-18
Graphql HIGH 7.5
CVE-2023-28104

`silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted gr…

Patch available
Fix from $1,950 2023-03-16
Rax30 Firmware HIGH 7.5
CVE-2023-28338

Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the req…

Mitigation only
Fix from $1,950 2023-03-15
Opensips HIGH 7.5
CVE-2023-27596

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, OpenSIPS crashes when a malformed SDP body …

Fix: 3.1.8 / 3.2.5+
Fix from $1,950 2023-03-15
Rack HIGH 7.5
CVE-2023-27530

A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an at…

Fix: 2.0.9.3 / 2.1.4.3+
Fix from $1,950 2023-03-10
Jenkins HIGH 7.5
CVE-2023-27900

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request par…

Fix: 2.375.4 / 2.394+
Fix from $1,950 2023-03-10
Jenkins HIGH 7.5
CVE-2023-27901

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request par…

Fix: 2.375.4 / 2.394+
Fix from $1,950 2023-03-10
Go HIGH 7.5
CVE-2022-41725

A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader…

Fix: 1.19.6+
Fix from $1,950 2023-02-28