Vulnerability index

Browse CVEs

2,041 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2024-53857 rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by provi… Mitigation only Fix from $1,9502024-12-05 HIGH 7.5 CVE-2024-48843 Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3… Aspect Ent 2 Firmware 3.08.03+ Fix from $1,9502024-12-05 MEDIUM 6.5 CVE-2024-48844 Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3… Aspect Ent 2 Firmware 3.08.03+ Fix from $1,6002024-12-05 HIGH 7.5 CVE-2024-11316 Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products: ABB ASPECT - Enterprise… Aspect Ent 2 Firmware 3.08.03+ Fix from $1,9502024-12-05 HIGH 7.5 CVE-2024-48080 An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier indicates that exploitation ca… Mitigation only Fix from $1,9502024-12-03 HIGH 7.5 CVE-2024-52805 Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increa… Synapse 1.120.1+ Fix from $1,9502024-12-03 HIGH 7.5 CVE-2024-37302 Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary c… Synapse 1.106.0+ Fix from $1,9502024-12-03 HIGH 7.5 CVE-2024-53981 python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of … Patch available Fix from $1,9502024-12-02 HIGH 7.5 CVE-2024-31669 rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_parse_var, and estimate_slide. Rizin 0.6.3+ Fix from $1,9502024-12-02 MEDIUM 5.3 CVE-2024-41761 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash u… Db2 Mitigation only Fix from $1,6002024-11-23 HIGH 7.5 CVE-2024-52804 Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2… Tornado 6.4.2+ Fix from $1,9502024-11-22 HIGH 7.5 CVE-2024-52797 Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and 14, Opencast's Elasticsearch… Opencast 13.10 / 14.3+ Fix from $1,9502024-11-21 HIGH 7.5 CVE-2024-52581 Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parser shipped with litestar expec… Litestar 2.13.0+ Fix from $1,9502024-11-20 HIGH 7.5 CVE-2024-48530 An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a … Esoft Planner No fix yet Fix from $1,9502024-11-20 MEDIUM 5.3 CVE-2024-52796 Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions p… Mitigation only Fix from $1,6002024-11-20 HIGH 7.5 CVE-2024-21539 Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitiza… Patch available Fix from $1,9502024-11-19 MEDIUM 5.5 CVE-2024-50285 In the Linux kernel, the following vulnerability has been resolved: ksmbd: check outstanding simultaneous SMB operations If Client send simultaneou… Linux Kernel 6.6.61 / 6.11.8+ Fix from $1,6002024-11-19 MEDIUM 5.5 CVE-2024-50271 In the Linux kernel, the following vulnerability has been resolved: signal: restore the override_rlimit logic Prior to commit d64696905554 ("Reimpl… Linux Kernel 6.1.117 / 6.6.61+ Fix from $1,6002024-11-19 HIGH 7.4 CVE-2021-1285 Multiple Cisco products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthen… Mitigation only Fix from $1,9502024-11-18 HIGH 7.5 CVE-2019-25220 Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Ch… Bitcoin Core 24.0.1+ Fix from $1,9502024-11-18 MEDIUM 5.3 CVE-2024-52913 In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are m… Bitcoin Core 0.21.0+ Fix from $1,6002024-11-18 HIGH 7.5 CVE-2024-52914 In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction. Bitcoin Core 0.18.0+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-52915 Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message. Bitcoin Core 0.20.0+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-52916 Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers. Bitcoin Core 0.15.0+ Fix from $1,9502024-11-18 MEDIUM 6.5 CVE-2024-52917 Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large… Bitcoin Core 22.0+ Fix from $1,6002024-11-18 MEDIUM 6.5 CVE-2024-52918 Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 … Mitigation only Fix from $1,6002024-11-18 HIGH 7.5 CVE-2024-52920 Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message. Bitcoin Core 0.20.0+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-3760 In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers… Lunary 1.2.8+ Fix from $1,9502024-11-14 MEDIUM 5.4 CVE-2024-4311 zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can … Zenml Patch available Fix from $1,6002024-11-14 HIGH 7.5 CVE-2024-50955 An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a crafted T… Mitigation only Fix from $1,9502024-11-13