Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Revel HIGH 7.5
CVE-2020-36568

Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocat…

Fix: 1.0.0+
Fix from $1,950 2022-12-27
Dhi Dss7016d S2 Firmware MEDIUM 5.9
CVE-2022-45434

Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall ac…

Patch available
Fix from $1,600 2022-12-27
Rdiffweb MEDIUM 6.5
CVE-2022-4723

Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.

Fix: 2.5.5+
Fix from $1,600 2022-12-27
Android HIGH 7.8
CVE-2022-42531

In mmu_map_for_fw of gs_ldfw_load.c, there is a possible mitigation bypass due to Permissive Memory Allocation. This could lead to local escalation o…

Mitigation only
Fix from $1,950 2022-12-16
Helm HIGH 7.5
CVE-2022-23524

Helm is a tool for managing Charts, pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption, r…

Fix: 3.10.3+
Fix from $1,950 2022-12-15
Android HIGH 7.8
CVE-2022-20478

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This coul…

Mitigation only
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20479

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This coul…

Mitigation only
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20480

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This coul…

Mitigation only
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20484

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This coul…

Mitigation only
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20485

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This coul…

Mitigation only
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20486

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This coul…

Mitigation only
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20487

In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This coul…

Mitigation only
Fix from $1,950 2022-12-13
Go MEDIUM 5.3
CVE-2022-41717EPSS 6%

An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys…

Fix: 0.4.0 / 1.18.9+
Fix from $1,600 2022-12-08
Libp2p HIGH 7.5
CVE-2022-23492

go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted res…

Fix: 0.18.0+
Fix from $1,950 2022-12-08
Libp2p HIGH 7.5
CVE-2022-23486

libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a vic…

Fix: 0.45.1+
Fix from $1,950 2022-12-07
Libp2p HIGH 7.5
CVE-2022-23487

js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted…

Fix: 0.38.0+
Fix from $1,950 2022-12-07
Xwiki MEDIUM 5.3
CVE-2022-41932

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new …

Fix: 13.10.8 / 14.4.2+
Fix from $1,600 2022-11-23
Mattermost MEDIUM 6.5
CVE-2022-4045

A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoint…

Mitigation only
Fix from $1,600 2022-11-23
Mattermost MEDIUM 6.5
CVE-2022-4019

A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to …

Mitigation only
Fix from $1,600 2022-11-23
Mattermost MEDIUM 6.5
CVE-2022-4044

A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.

Fix: 7.4+
Fix from $1,600 2022-11-23
Hub HIGH 7.5
CVE-2022-45471

In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address

Fix: 2022.3.15181+
Fix from $1,950 2022-11-18
Secure Firewall Threat Defense MEDIUM 5.3
CVE-2022-20950

A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attack…

Mitigation only
Fix from $1,600 2022-11-15
Fl Mguard Centerport Firmware HIGH 7.5
CVE-2022-3480

A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending …

Fix: 8.9.0+
Fix from $1,950 2022-11-15
Concrete Cms MEDIUM 6.5
CVE-2022-43686

In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can be filled up causing a denial …

Fix: 8.5.10+
Fix from $1,600 2022-11-14
750 8100 Firmware HIGH 7.5
CVE-2021-34568

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provo…

Fix: 18+
Fix from $1,950 2022-11-09
Linux Kernel HIGH 7.5
CVE-2022-43945EPSS 22%

The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by e…

Fix: 5.19.17 / 6.0.2+
Fix from $1,950 2022-11-04
Fedora MEDIUM 6.5
CVE-2022-42311

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42312

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42313

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01
Debian Linux MEDIUM 6.5
CVE-2022-42314

Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabi…

Patch available
Fix from $1,600 2022-11-01