Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Image MEDIUM 5.5
CVE-2022-41727

An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a deni…

Fix: 0.5.0+
Fix from $1,600 2023-02-28
Curl MEDIUM 6.5
CVE-2023-23916

An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, mea…

Fix: 7.88.0+
Fix from $1,600 2023-02-23
Hyper HIGH 7.5
CVE-2022-31394

Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers …

Fix: 0.14.19+
Fix from $1,950 2023-02-21
Knot Resolver HIGH 7.5
CVE-2023-26249

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. S…

Fix: 5.6.0+
Fix from $1,950 2023-02-21
Octobox HIGH 7.5
CVE-2021-32848

Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted searc…

Fix: 2021-11-02+
Fix from $1,950 2023-02-20
Commons Fileupload HIGH 7.5
CVE-2023-24998EPSS 47%

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin…

Fix: 1.5+
Fix from $1,950 2023-02-20
Notation Go HIGH 7.5
CVE-2023-25656

notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation…

Mitigation only
Fix from $1,950 2023-02-20
Peazip MEDIUM 5.5
CVE-2023-24785

An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA fea…

No fix yet
Fix from $1,600 2023-02-17
Containerd MEDIUM 5.5
CVE-2023-25153

containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of b…

Fix: 1.5.18 / 1.6.18+
Fix from $1,600 2023-02-16
PHP HIGH 8.1
CVE-2023-0568

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv…

Fix: 8.0.28 / 8.1.16+
Fix from $1,950 2023-02-16
Kiwi Tcms CRITICAL 9.8
CVE-2023-25156

Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force …

Fix: 12.0+
Fix from $2,300 2023-02-15
Kiwi Tcms MEDIUM 5.9
CVE-2023-25171

Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-se…

Fix: 12.0+
Fix from $1,600 2023-02-15
Starlite HIGH 7.5
CVE-2023-25578

Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing in `starlite` allows a potent…

Fix: 1.51.2+
Fix from $1,950 2023-02-15
Werkzeug HIGH 7.5
CVE-2023-25577

Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited numbe…

Fix: 2.2.3+
Fix from $1,950 2023-02-14
Fastify Multipart HIGH 7.5
CVE-2023-25576

@fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/multipart may experience deni…

Fix: 6.0.1 / 7.4.1+
Fix from $1,950 2023-02-14
Fedora HIGH 7.5
CVE-2023-25193

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back…

Fix: after 6.0.0
Fix from $1,950 2023-02-04
Django HIGH 7.5
CVE-2023-23969EPSS 47%

In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repeti…

Fix: 3.2.17 / 4.0.9+
Fix from $1,950 2023-02-01
Big Ip Access Policy Manager HIGH 7.5
CVE-2023-22323

In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when O…

Fix: 14.1.5.3 / 15.1.8.1+
Fix from $1,950 2023-02-01
Open5gs HIGH 7.5
CVE-2023-23846

Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS …

Fix: 2.4.13+
Fix from $1,950 2023-02-01
Discourse MEDIUM 6.5
CVE-2023-22740

Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of R…

Fix: after 3.0.0
Fix from $1,600 2023-01-27
Discourse MEDIUM 6.5
CVE-2023-22739

Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) a…

Fix: 3.0.1+
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2022-20494

In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of servi…

Mitigation only
Fix from $1,600 2023-01-26
Android HIGH 7.8
CVE-2022-20489

In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead t…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2022-20490

In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could le…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2022-20492

In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead t…

Mitigation only
Fix from $1,950 2023-01-26
Android HIGH 7.8
CVE-2022-20456

In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead…

Mitigation only
Fix from $1,950 2023-01-26
Webex Room Phone Firmware MEDIUM 6.5
CVE-2023-20047

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenti…

Fix: after 1.2.0
Fix from $1,600 2023-01-20
Sz 300 Firmware HIGH 7.5
CVE-2021-36630

DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote attackers to perform DOS attack…

Fix: after 3.6.2
Fix from $1,950 2023-01-18
Junos Os Evolved MEDIUM 6.1
CVE-2023-22397

An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Packet Forwarding Engine (PFE) on Juniper Networks J…

Fix: 20.4+
Fix from $1,600 2023-01-13
Junos HIGH 7.5
CVE-2023-22403

An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a net…

Fix: 20.2+
Fix from $1,950 2023-01-13