Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 6.5 CVE-2023-42504 An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial… Superset 3.0.0+ Fix from $1,6002023-11-28 HIGH 7.5 CVE-2023-6117 A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server … M Files Server after 23.11.13156.0 Fix from $1,9502023-11-22 HIGH 7.8 CVE-2023-38543 A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo… Secure Access Client 22.6+ Fix from $1,9502023-11-15 HIGH 7.5 CVE-2023-47108 OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. Starting in version 0.37.0 and prior to version 0.46.0, the gr… Opentelemetry 0.46.0+ Fix from $1,9502023-11-10 HIGH 7.5 CVE-2023-47120 Discourse is an open source platform for community discussion. In versions 3.1.0 through 3.1.2 of the `stable` branch and versions 3.1.0,beta6 throug… Discourse 3.1.3+ Fix from $1,9502023-11-10 MEDIUM 5.4 CVE-2023-46130 Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` an… Discourse 3.1.3 / 3.2.0+ Fix from $1,6002023-11-10 HIGH 7.5 CVE-2023-44271 An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially … Pillow 10.0.0+ Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-46695EPSS 50% An issue was discovered in Django 3.2 before 3.2.23, 4.1 before 4.1.13, and 4.2 before 4.2.7. The NFKC normalization is slow on Windows. As a consequ… Django 3.2.23 / 4.1.13+ Fix from $1,9502023-11-02 MEDIUM 6.5 CVE-2023-20155 A vulnerability in a logging API in Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause the dev… Secure Firewall Management Center after 7.3.1.1 Fix from $1,6002023-11-01 HIGH 7.5 CVE-2023-5625 A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2… Openshift Container Platform For Arm64 Patch available Fix from $1,9502023-11-01 MEDIUM 5.5 CVE-2023-45862 An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potent… Linux Kernel 6.2.5+ Fix from $1,6002023-10-14 HIGH 7.5 CVE-2023-45130 Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the end of a contract execution, w… Frontier after 0.1.0 Fix from $1,9502023-10-13 MEDIUM 6.5 CVE-2023-5573 Allocation of Resources Without Limits or Throttling in GitHub repository vriteio/vrite prior to 0.3.0. Vrite 0.3.0+ Fix from $1,6002023-10-13 HIGH 7.5 CVE-2023-44191 An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker … Junos Mitigation only Fix from $1,9502023-10-13 HIGH 7.5 CVE-2023-5072 Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to ind… Json Java after 20230618 Fix from $1,9502023-10-12 HIGH 7.5 CVE-2023-45142 OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent`… Opentelemetry 0.44.0+ Fix from $1,9502023-10-12 HIGH 7.5 CVE-2023-39325 A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total… Go 0.17.0 / 1.20.10+ Fix from $1,9502023-10-11 HIGH 7.5 CVE-2023-40542 When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory res… Big Ip Access Policy Manager 15.1.9 / 16.1.4+ Fix from $1,9502023-10-10 MEDIUM 6.5 CVE-2023-25822 ReportPortal is an AI-powered test automation platform. Prior to version 5.10.0 of the `com.epam.reportportal:service-api` module, corresponding to R… Reportportal 5.10.0 / 23.2+ Fix from $1,6002023-10-09 HIGH 7.5 CVE-2023-5330 Mattermost fails to enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to t… Mattermost Server 7.8.11 / 8.0.3+ Fix from $1,9502023-10-09 HIGH 7.5 CVE-2023-45371 An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There … Mediawiki 1.35.12 / 1.39.5+ Fix from $1,9502023-10-09 MEDIUM 6.5 CVE-2023-5371 RTPS dissector memory leak in Wireshark 4.0.0 to 4.0.8 and 3.6.0 to 3.6.16 allows denial of service via packet injection or crafted capture file Wireshark 3.6.17 / 4.0.9+ Fix from $1,6002023-10-04 MEDIUM 5.3 CVE-2023-3153 A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a de… Openshift Container Platform 22.03.3 / 22.09.2+ Fix from $1,6002023-10-04 HIGH 7.5 CVE-2023-3967 Allocation of Resources Without Limits or Throttling vulnerability in Hitachi Ops Center Common Services on Linux allows DoS.This issue affects Hitac… Ops Center Common Services 10.9.3-00+ Fix from $1,9502023-10-03 MEDIUM 5.3 CVE-2023-0809 In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets. Mosquitto 2.0.16+ Fix from $1,6002023-10-02 HIGH 8.8 CVE-2023-5289 Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4. Rdiffweb 2.8.4+ Fix from $1,9502023-09-29 HIGH 8.6 CVE-2023-20033 A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to… Ios Xe Mitigation only Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-43642 snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to… Snappy Java 1.1.10.4+ Fix from $1,9502023-09-25 HIGH 7.5 CVE-2023-42457 plone.rest allows users to use HTTP verbs such as GET, POST, PUT, DELETE, etc. in Plone. Starting in the 2.x branch and prior to versions 2.0.1 and 3… Rest Patch available Fix from $1,9502023-09-21 CRITICAL 9.9 CVE-2023-43632 As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM t… Edge Virtualization Engine 9.5.0+ Fix from $2,3002023-09-21