Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Team\+ Pro MEDIUM 6.5
CVE-2022-35220

Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A remote attacker with general…

Fix: after 3.011.6.0.1
Fix from $1,600 2022-08-02
Team\+ Pro MEDIUM 5.4
CVE-2022-35221

Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread subject field. A remote attack…

Fix: after 3.011.6.0.1
Fix from $1,600 2022-08-02
Fedora HIGH 7.5
CVE-2022-35922

Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memo…

Fix: 0.26.5+
Fix from $1,950 2022-08-01
Contracts MEDIUM 5.3
CVE-2022-35915

OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbo…

Fix: 4.7.2+
Fix from $1,600 2022-08-01
Discourse HIGH 7.5
CVE-2022-31184

Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to send mass spam emails. A fix has…

Fix: after 2.8.6
Fix from $1,950 2022-08-01
Junos Os Evolved HIGH 7.5
CVE-2022-22212

An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allo…

Mitigation only
Fix from $1,950 2022-07-20
Team\+ Pro MEDIUM 6.5
CVE-2022-32958

A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size limit, to terminate other rec…

Fix: after 3.011.6.0.1
Fix from $1,600 2022-07-20
Pexip Infinity HIGH 7.5
CVE-2022-29286

Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because of registrar resource mishand…

Fix: 28.0+
Fix from $1,950 2022-07-17
Mattermost MEDIUM 6.5
CVE-2022-2406

The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported files, which allows an authenti…

Fix: after 6.5.1
Fix from $1,600 2022-07-14
Kubeedge MEDIUM 6.5
CVE-2022-31075

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31078

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31079

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Kubeedge MEDIUM 6.5
CVE-2022-31080

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.…

Fix: 1.9.4 / 1.10.2+
Fix from $1,600 2022-07-11
Glftpd HIGH 7.5
CVE-2021-31645

An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.

No fix yet
Fix from $1,950 2022-07-07
Curl MEDIUM 6.5
CVE-2022-32206EPSS 32%

curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with dif…

Fix: 7.84.0+
Fix from $1,600 2022-07-07
Mediawiki HIGH 7.5
CVE-2022-34750

An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thousand characters. Unfortunatel…

Fix: after 1.38.1
Fix from $1,950 2022-06-28
Gpac MEDIUM 5.5
CVE-2021-40607

The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.

Fix: 2.0.0+
Fix from $1,600 2022-06-28
Gpac MEDIUM 5.5
CVE-2021-40609

The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.

Fix: 2.0.0+
Fix from $1,600 2022-06-28
Bento4 HIGH 7.5
CVE-2021-40941

In Bento4 1.6.0-638, there is an allocator is out of memory in the function AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity in Ap4Array.h:172, as demo…

No fix yet
Fix from $1,950 2022-06-27
Argo Cd MEDIUM 6.5
CVE-2022-31016

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption…

Fix: 2.1.16 / 2.2.10+
Fix from $1,600 2022-06-25
Manager Server HIGH 7.5
CVE-2022-21952

A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote atta…

Fix: 4.1.46 / 4.2.37+
Fix from $1,950 2022-06-22
Spring Cloud Function HIGH 7.5
CVE-2022-22979

In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to ca…

Fix: 3.2.6+
Fix from $1,950 2022-06-21
3ds Max HIGH 7.8
CVE-2022-27871

Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the al…

Mitigation only
Fix from $1,950 2022-06-21
Inventree MEDIUM 6.5
CVE-2022-2134

Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.

Fix: 0.8.0+
Fix from $1,600 2022-06-20
Ua .net Standard Stack HIGH 7.5
CVE-2022-29863

OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.

Fix: 1.4.368.58+
Fix from $1,950 2022-06-16
Android MEDIUM 5.5
CVE-2022-20143

In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local de…

Mitigation only
Fix from $1,600 2022-06-15
Couchbase Server CRITICAL 9.1
CVE-2022-32559

An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.

Fix: 7.0.4+
Fix from $2,300 2022-06-14
Ar8035 Firmware HIGH 7.5
CVE-2021-35096

Improper memory allocation during counter check DLM handling can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect…

Mitigation only
Fix from $1,950 2022-06-14
Bento4 MEDIUM 5.5
CVE-2022-31285

An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.

No fix yet
Fix from $1,600 2022-06-10
Bento4 MEDIUM 5.5
CVE-2022-31287

An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.

No fix yet
Fix from $1,600 2022-06-10