Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HTTP Server HIGH 7.5
CVE-2022-29404EPSS 6%

In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no defau…

Fix: after 2.4.53
Fix from $1,950 2022-06-09
HTTP Server HIGH 7.5
CVE-2022-30522EPSS 90%

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m…

Mitigation only
Fix from $1,950 2022-06-09
Cri O HIGH 7.5
CVE-2022-1708

A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync reque…

Fix: 1.19.7 / 1.20.8+
Fix from $1,950 2022-06-07
Adbyby MEDIUM 6.5
CVE-2022-29767

adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a Denial of Service (DoS) via h…

No fix yet
Fix from $1,600 2022-06-03
Tika MEDIUM 5.5
CVE-2022-25169

The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.

Fix: 1.28.2 / 2.4.0+
Fix from $1,600 2022-05-16
Xpdf MEDIUM 5.5
CVE-2022-30775

xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the …

No fix yet
Fix from $1,600 2022-05-16
Spring Framework MEDIUM 5.3
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS att…

Fix: after 5.3.19
Fix from $1,600 2022-05-12
Spring Framework MEDIUM 6.5
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable …

Fix: after 5.3.19
Fix from $1,600 2022-05-12
Android MEDIUM 5.5
CVE-2021-39670

In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local de…

Patch available
Fix from $1,600 2022-05-10
Secure Firewall Threat Defense HIGH 7.5
CVE-2022-20751

A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote at…

Fix: 6.4.0.15 / 6.6.5.2+
Fix from $1,950 2022-05-03
Secure Firewall Threat Defense HIGH 7.5
CVE-2022-20757

A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker …

Fix: 6.4.0.15 / 6.6.5.2+
Fix from $1,950 2022-05-03
Secure Firewall Threat Defense HIGH 7.5
CVE-2022-20767

A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacke…

Fix: 7.0.2+
Fix from $1,950 2022-05-03
Tz300p Firmware HIGH 7.5
CVE-2022-22278

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try t…

Fix: 7.0.1 / 7.0.1.0+
Fix from $1,950 2022-04-27
Zammad HIGH 7.5
CVE-2022-29701

A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legiti…

Patch available
Fix from $1,950 2022-04-27
Atlant HIGH 7.5
CVE-2022-28871

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain F-Secure products while scann…

Mitigation only
Fix from $1,950 2022-04-25
Gt.m HIGH 7.5
CVE-2021-44502

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a m…

Fix: after 7.0-000
Fix from $1,950 2022-04-15
Sd Wan Vedge Router MEDIUM 5.5
CVE-2022-20717

A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run …

Fix: after 20.6
Fix from $1,600 2022-04-15
Aironet Access Point Software HIGH 7.5
CVE-2022-20622

A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthe…

Fix: 17.3.4 / 17.6.1+
Fix from $1,950 2022-04-15
Playbooks MEDIUM 6.5
CVE-2022-1333

Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorize…

Fix: after 1.24.0
Fix from $1,600 2022-04-13
Mattermost Server MEDIUM 6.5
CVE-2022-1337

The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authentica…

Fix: 5.37.9 / 6.2.5+
Fix from $1,600 2022-04-13
Swhkd MEDIUM 5.3
CVE-2022-27819

SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon…

Patch available
Fix from $1,600 2022-04-07
GitLab MEDIUM 5.3
CVE-2022-1121

A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 …

Fix: 14.7.7 / 14.8.5+
Fix from $1,600 2022-04-04
Spring Framework MEDIUM 6.5
CVE-2022-22950EPSS 36%

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression t…

Fix: 5.2.20 / 5.3.17+
Fix from $1,600 2022-04-01
App Connect Enterprise Certified Container MEDIUM 6.5
CVE-2022-22404

IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulne…

Fix: 4.0.0+
Fix from $1,600 2022-04-01
Ex300 V2 Firmware MEDIUM 6.5
CVE-2021-43662

totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption.

No fix yet
Fix from $1,600 2022-03-31
Interest Security Scanner HIGH 7.5
CVE-2017-20016

A vulnerability has been found in WEKA INTEREST Security Scanner up to 1.8 and classified as problematic. This vulnerability affects unknown code of …

Fix: after 1.8
Fix from $1,950 2022-03-28
Federated Learning Application Runtime Environment HIGH 7.5
CVE-2022-21822

NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Thr…

Fix: 2.0.16+
Fix from $1,950 2022-03-17
Moodle HIGH 7.5
CVE-2021-32476

A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.…

Fix: 3.5.18 / 3.8.9+
Fix from $1,950 2022-03-11
Nextcloud Server MEDIUM 6.5
CVE-2022-24741

Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uplo…

Fix: 21.0.8 / 22.2.4+
Fix from $1,600 2022-03-09
Poi MEDIUM 5.5
CVE-2022-26336

A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read…

Fix: 5.2.1+
Fix from $1,600 2022-03-04