Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2023-37279
Faktory is a language-agnostic persistent background job server. Prior to version 1.8.0, the Faktory web dashboard can suffer from denial of service …
Faktory
1.8.0+
HIGH 7.5
CVE-2022-47562
Vulnerability in the RCPbind service running on UDP port (111), allowing a remote attacker to create a denial of service (DoS) condition.
Ekorccp Firmware
Mitigation only
HIGH 7.5
CVE-2023-32186
A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor p…
Rancher Rke2
1.24.17 / 1.25.13+
HIGH 7.5
CVE-2023-32187
An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supervisor p…
K3s
1.24.17 / 1.25.13+
MEDIUM 6.5
CVE-2023-40588
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passe…
Discourse
3.1.1+
MEDIUM 6.5
CVE-2023-41042
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passe…
Discourse
3.1.1+
MEDIUM 6.5
CVE-2023-41043
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passe…
Discourse
3.1.1+
MEDIUM 6.5
CVE-2023-38706
Discourse is an open-source discussion platform. Prior to version 3.1.1 of the `stable` branch and version 3.2.0.beta1 of the `beta` and `tests-passe…
Discourse
3.1.0+
MEDIUM 6.5
CVE-2023-40019
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation tha…
Freeswitch
1.10.10+
CRITICAL 9.8
CVE-2023-38507
Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's adm…
Strapi
4.12.1+
HIGH 7.5
CVE-2023-38039EPSS 62%
When curl retrieves an HTTP response, it stores the incoming headers so that
they can be accessed later via the libcurl headers API.
However, curl d…
Curl
8.3.0 / 10.0.17763.5122+
MEDIUM 6.5
CVE-2023-4578
When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the fun…
Firefox
115.2 / 117.0+
HIGH 7.5
CVE-2023-39322
QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection …
Go
1.21.1+
HIGH 7.5
CVE-2023-4647
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.1.5, all versions starting from 16.2 before 16.2.5, all ve…
GitLab
16.1.5 / 16.2.5+
HIGH 7.5
CVE-2023-40709
An adversary could crash the entire device by sending a large quantity of ICMP requests if the controller has the built-in web server enabled but doe…
Snap Pac S1 Firmware
Mitigation only
HIGH 7.5
CVE-2023-40710
An adversary could cause a continuous restart loop to the entire device by sending a large quantity of HTTP GET requests if the controller has the bu…
Snap Pac S1 Firmware
Mitigation only
MEDIUM 5.5
CVE-2022-48064
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_a…
Fedora
2.40+
HIGH 7.5
CVE-2023-33953
gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional…
Grpc
1.53.2 / 1.54.3+
HIGH 7.5
CVE-2023-39533
go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys…
Go Libp2p
0.27.8 / 0.28.2+
HIGH 7.5
CVE-2023-39269
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCO…
Ruggedcom Ros
4.3.8+
MEDIUM 5.5
CVE-2023-38532
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All v…
Parasolid
14.1.0.11 / 14.2.0.6+
MEDIUM 6.5
CVE-2023-4138
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.
Rdiffweb
2.8.0+
MEDIUM 6.5
CVE-2023-29408
The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (bot…
Image
0.10.0+
HIGH 7.5
CVE-2022-46485
Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey contains a "Text Field", "Co…
Ngsurvey
after 2.4.28
HIGH 7.5
CVE-2023-4011
An issue has been discovered in GitLab EE affecting all versions from 15.11 prior to 16.2.2 which allows an attacker to spike the resource consumptio…
GitLab
16.2.2+
MEDIUM 5.3
CVE-2023-4046
In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a po…
Firefox
102.14 / 115.1+
MEDIUM 6.5
CVE-2023-38498
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passe…
Discourse
3.0.6+
HIGH 7.5
CVE-2023-38684
Discourse is an open source discussion platform. Prior to version 3.0.6 of the `stable` branch and version 3.1.0.beta7 of the `beta` and `tests-passe…
Discourse
3.0.6+
HIGH 7.5
CVE-2023-38492
Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with…
Kirby
3.5.8.3 / 3.6.6.3+
MEDIUM 5.9
CVE-2023-3242
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based…
Automation Runtime
Mitigation only