Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2024-39474
In the Linux kernel, the following vulnerability has been resolved:
mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL
commi…
Linux Kernel
5.17 / 6.1.95+
MEDIUM 5.5
CVE-2024-39477
In the Linux kernel, the following vulnerability has been resolved:
mm/hugetlb: do not call vma_add_reservation upon ENOMEM
sysbot reported a splat…
Linux Kernel
6.9.5+
MEDIUM 5.5
CVE-2024-39478
In the Linux kernel, the following vulnerability has been resolved:
crypto: starfive - Do not free stack buffer
RSA text data uses variable length …
Linux Kernel
6.9.5+
MEDIUM 5.5
CVE-2024-39482
In the Linux kernel, the following vulnerability has been resolved:
bcache: fix variable length array abuse in btree_iter
btree_iter is used in two…
Linux Kernel
5.10.221 / 5.15.162+
MEDIUM 5.5
CVE-2024-39484
In the Linux kernel, the following vulnerability has been resolved:
mmc: davinci: Don't strip remove function when driver is builtin
Using __exit f…
Linux Kernel
2.6.33 / 5.10.221+
HIGH 7.5
CVE-2024-6427
Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to…
Mesbook
Mitigation only
HIGH 7.5
CVE-2024-37298
gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of typ…
Patch available
HIGH 7.5
CVE-2024-34703
Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of …
Patch available
HIGH 7.5
CVE-2024-38528
nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing limit for accepted NTS-KE conne…
Mitigation only
HIGH 7.5
CVE-2024-35116
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes. …
Mq
9.0.0.26 / 9.1.0.22+
HIGH 7.5
CVE-2024-31919
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error proce…
Mq
Mitigation only
MEDIUM 6.5
CVE-2024-37681
An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote attacker to cause a denial of ser…
No fix yet
HIGH 7.8
CVE-2024-34027
In the Linux kernel, the following vulnerability has been resolved:
f2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem loc…
Linux Kernel
5.10.219 / 5.15.161+
MEDIUM 6.5
CVE-2024-5208
An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows atta…
Anythingllm
1.0.0+
MEDIUM 5.3
CVE-2024-37309
CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) pe…
Cratedb
5.7.2+
MEDIUM 6.5
CVE-2024-31881
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash w…
Db2
Mitigation only
MEDIUM 6.5
CVE-2024-28762
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted qu…
Db2
Mitigation only
MEDIUM 6.5
CVE-2024-34055
Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in …
Cyrus Imap
3.8.3+
MEDIUM 5.5
CVE-2022-28656
is_closing_session() allows users to consume RAM in the Apport process
Ubuntu Linux
2.21.0+
MEDIUM 5.5
CVE-2022-28654
is_closing_session() allows users to fill up apport.log
Ubuntu Linux
2.21.0+
HIGH 7.1
CVE-2022-28655
is_closing_session() allows users to create arbitrary tcp dbus connections
Ubuntu Linux
2.21.0+
HIGH 7.5
CVE-2024-32871
Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. B…
Pimcore
11.2.4+
HIGH 7.5
CVE-2024-36378
In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens
Teamcity
2024.03.2+
MEDIUM 5.3
CVE-2024-35238
Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerable to a denial-of-service (Do…
Patch available
HIGH 8.6
CVE-2024-35231
rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vu…
Patch available
HIGH 7.8
CVE-2021-47551
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/amdkfd: Fix kernel panic when reset failed and been triggered again
In …
Linux Kernel
5.10.84 / 5.15.7+
MEDIUM 6.5
CVE-2024-2874
An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17.0 before 17.0.1. A runner re…
GitLab
16.10.6 / 16.11.3+
MEDIUM 5.3
CVE-2024-31617
OpenLiteSpeed before 1.8.1 mishandles chunked encoding.
Openlitespeed
1.8.1+
MEDIUM 5.5
CVE-2021-47374
In the Linux kernel, the following vulnerability has been resolved:
dma-debug: prevent an error message from causing runtime problems
For some driv…
Linux Kernel
5.14.9+
HIGH 8.8
CVE-2024-35969
In the Linux kernel, the following vulnerability has been resolved:
ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr
Although ipv…
Linux Kernel
4.19.313 / 5.4.275+