Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2023-6516 To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods… Bind after 9.16.45 Fix from $1,9502024-02-13 MEDIUM 6.5 CVE-2024-21875 Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team Hacker Hotel Badge 2024 on ris… Hacker Hotel Badge 2024 after 0.1.3 Fix from $1,6002024-02-11 HIGH 7.5 CVE-2023-52428 In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka i… Nimbus Jose\+jwt 9.37.2+ Fix from $1,9502024-02-11 HIGH 7.5 CVE-2023-52427 In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_samples. NOTE: the vendor's positio… Opendds after 3.27 Fix from $1,9502024-02-11 MEDIUM 6.5 CVE-2024-1066 An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which al… GitLab 16.6.7 / 16.7.5+ Fix from $1,6002024-02-07 MEDIUM 6.5 CVE-2024-25143 The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 b… Digital Experience Platform 7.2 / 7.2.0+ Fix from $1,6002024-02-07 MEDIUM 6.5 CVE-2024-24752 Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, th… Bref 2.1.13+ Fix from $1,6002024-02-01 MEDIUM 5.7 CVE-2024-23826 spbu_se_site is the website of the Department of System Programming of St. Petersburg State University. Before 2024.01.29, when uploading an avatar i… Spbu Se Site 2024.01.29+ Fix from $1,6002024-01-29 MEDIUM 6.5 CVE-2024-23820 OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In some scenarios that depend on… Openfga 1.4.3+ Fix from $1,6002024-01-26 CRITICAL 9.8 CVE-2021-42142 An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoch number. This vuln… Tinydtls after 2018-08-30 Fix from $2,3002024-01-23 MEDIUM 6.5 CVE-2023-47746 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to c… Db2 after 11.5.9 Fix from $1,6002024-01-22 MEDIUM 5.5 CVE-2023-28899 By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service of ot… Superb 3 Firmware Mitigation only Fix from $1,6002024-01-12 HIGH 7.5 CVE-2024-21604 An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, n… Junos Os Evolved Mitigation only Fix from $1,9502024-01-12 MEDIUM 6.5 CVE-2023-37934 An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perf… Fortipam 1.1.0+ Fix from $1,6002024-01-10 HIGH 7.5 CVE-2023-6476 A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get a… Openshift Container Platform Mitigation only Fix from $1,9502024-01-09 HIGH 7.5 CVE-2024-0241 encoded_id-rails versions before 1.0.0.beta2 are affected by an uncontrolled resource consumption vulnerability. A remote and unauthenticated attacke… Encodedid\ 1.0.0+ Fix from $1,9502024-01-04 HIGH 7.5 CVE-2024-21634 Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in `ion-java` for a… Ion 1.10.5+ Fix from $1,9502024-01-03 MEDIUM 6.5 CVE-2023-46738 CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that c… Cubefs 3.3.1+ Fix from $1,6002024-01-03 HIGH 7.5 CVE-2023-3171 A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502023-12-27 HIGH 7.5 CVE-2023-50730 Grackle is a GraphQL server written in functional Scala, built on the Typelevel stack. The GraphQL specification requires that GraphQL fragments must… Grackle 0.18.0+ Fix from $1,9502023-12-22 MEDIUM 6.5 CVE-2023-6910 A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust serve… M Files Server 23.12.13195.0+ Fix from $1,6002023-12-20 HIGH 7.7 CVE-2023-6563 An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline toke… Keycloak 21.0.0+ Fix from $1,9502023-12-14 HIGH 7.5 CVE-2023-5379 A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-50247 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The QUIC stack (quicly), as used by H2O up to commit 43f86e5 (in version 2.3.0-be… H2o after 2.2.6 Fix from $1,9502023-12-12 HIGH 7.5 CVE-2023-50455 An issue was discovered in Zammad before 6.2.0. Due to lack of rate limiting in the "email address verification" feature, an attacker could send many… Zammad Mitigation only Fix from $1,9502023-12-10 HIGH 7.5 CVE-2023-6337 HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large… Vault 1.13.12 / 1.14.8+ Fix from $1,9502023-12-08 HIGH 7.5 CVE-2023-4486 Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC e… Nae55 Firmware 12.0.4+ Fix from $1,9502023-12-07 HIGH 7.5 CVE-2023-48831 A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion. Availability Booking Calendar No fix yet Fix from $1,9502023-12-07 MEDIUM 6.5 CVE-2023-4912 An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all… GitLab 16.4.3 / 16.5.3+ Fix from $1,6002023-12-01 MEDIUM 6.5 CVE-2023-34389 An allocation of resources without limits or throttling vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote authent… Sel 451 Firmware Mitigation only Fix from $1,6002023-11-30