Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 6.5 CVE-2024-52973 An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/log_entries/summa… Kibana 7.17.23 / 8.14.2+ Fix from $1,6002025-01-21 HIGH 7.5 CVE-2024-43709 An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a special… Elasticsearch 7.17.21 / 8.13.3+ Fix from $1,9502025-01-21 HIGH 7.5 CVE-2024-41742 IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operation… Txseries For Multiplatforms Mitigation only Fix from $1,9502025-01-19 HIGH 7.5 CVE-2024-41743 IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocati… Txseries For Multiplatforms Mitigation only Fix from $1,9502025-01-19 HIGH 7.5 CVE-2024-45662 IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denia… Safer Payments 6.4.2.08 / 6.5.0.06+ Fix from $1,9502025-01-18 HIGH 7.5 CVE-2024-36403 Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded di… Matrix Media Repo 1.3.5+ Fix from $1,9502025-01-16 HIGH 7.5 CVE-2018-25108 An unauthenticated remote attacker can cause a DoS in the controller due to uncontrolled resource consumption. Mitigation only Fix from $1,9502025-01-16 HIGH 7.5 CVE-2024-56374 An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed… Django 4.2.18 / 5.0.11+ Fix from $1,9502025-01-14 MEDIUM 5.3 CVE-2024-46666 An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all vers… Fortios 7.2.9 / 7.4.5+ Fix from $1,6002025-01-14 HIGH 7.5 CVE-2024-46667 A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, … Fortisiem 7.1.6+ Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-46668 An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8… Fortios 6.4.16 / 7.0.16+ Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-57662 An issue in the sqlg_hash_source component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQ… Virtuoso No fix yet Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-57663 An issue in the sqlg_place_dpipes component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted S… Virtuoso No fix yet Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-57664 An issue in the sqlg_group_node component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL… Virtuoso No fix yet Fix from $1,9502025-01-14 MEDIUM 6.5 CVE-2024-46921 An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W100… Exynos 1080 Firmware Mitigation only Fix from $1,6002025-01-13 MEDIUM 5.5 CVE-2022-22491 IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12… App Connect Enterprise Certified Container after 12.4 Fix from $1,6002025-01-09 MEDIUM 5.3 CVE-2024-56332 Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, … Next.js 13.5.8 / 14.2.21+ Fix from $1,6002025-01-03 MEDIUM 5.5 CVE-2022-49035 In the Linux kernel, the following vulnerability has been resolved: media: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE I expect that the hardware wi… Linux Kernel 4.9.333 / 4.14.299+ Fix from $1,6002025-01-02 HIGH 8.2 CVE-2024-53647 Trend Micro ID Security, version 3.0 and below contains a vulnerability that could allow an attacker to send an unlimited number of email verificatio… Id Security after 3.0 Fix from $1,9502024-12-31 MEDIUM 5.5 CVE-2024-56722 In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix cpu stuck caused by printings during reset During reset, cmd to d… Linux Kernel 6.1.120 / 6.6.64+ Fix from $1,6002024-12-29 MEDIUM 5.5 CVE-2024-56584 In the Linux kernel, the following vulnerability has been resolved: io_uring/tctx: work around xa_store() allocation error issue syzbot triggered t… Linux Kernel 6.1.120 / 6.6.66+ Fix from $1,6002024-12-27 HIGH 7.5 CVE-2024-54538 A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1… Ipados 2.1 / 11.1+ Fix from $1,9502024-12-20 MEDIUM 6.5 CVE-2023-30443 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu… Db2 Mitigation only Fix from $1,6002024-12-19 HIGH 7.5 CVE-2024-56319 In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a den… Patch available Fix from $1,9502024-12-18 MEDIUM 5.5 CVE-2024-54501 The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2… Ipados 2.2 / 11.2+ Fix from $1,6002024-12-12 CRITICAL 9.8 CVE-2024-44241 The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be able to … Ipados 18.1+ Fix from $2,3002024-12-12 MEDIUM 5.3 CVE-2024-55563 Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outc… Bitcoin Core after 27.2 Fix from $1,6002024-12-09 MEDIUM 6.5 CVE-2024-41762 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u… Db2 after 11.5.9 Fix from $1,6002024-12-07 HIGH 7.5 CVE-2024-12254 Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain t… Patch available Fix from $1,9502024-12-06 HIGH 7.5 CVE-2024-53907 An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter a… Django 4.2.17 / 5.0.10+ Fix from $1,9502024-12-06