Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
MEDIUM 5.3 CVE-2023-26048 Jetty is a java based web server and servlet engine. In affected versions servlets with multipart support (e.g. annotated with `@MultipartConfig`) th… Jetty 9.4.51 / 10.0.14+ Fix from $1,6002023-04-18 MEDIUM 5.3 CVE-2023-28968 An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application… Appid Service Sigpack 1.550.2-31 / 5.7.0-47+ Fix from $1,6002023-04-17 HIGH 7.5 CVE-2018-15472 An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter … GitLab 11.1.7 / 11.2.4+ Fix from $1,9502023-04-15 HIGH 7.5 CVE-2023-27643 An issue found in POWERAMP 925-bundle-play and Poweramp 954-uni allows a remote attacker to cause a denial of service via the Rescan button in Queue … Poweramp No fix yet Fix from $1,9502023-04-14 HIGH 7.5 CVE-2023-27653 An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a denial of service via the SharedPreference files. Who No fix yet Fix from $1,9502023-04-14 HIGH 7.5 CVE-2023-30636 TiKV 6.1.2 allows remote attackers to cause a denial of service (fatal error, with RpcStatus UNAVAILABLE for "not leader") upon an attempt to start a… Tikv No fix yet Fix from $1,9502023-04-13 MEDIUM 5.5 CVE-2023-29573 Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component. Bento4 No fix yet Fix from $1,6002023-04-13 MEDIUM 5.3 CVE-2023-25414 Aten PE8108 2.4.232 is vulnerable to denial of service (DOS). Pe8108 Firmware No fix yet Fix from $1,6002023-04-11 HIGH 7.5 CVE-2023-26964 An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the m… H2 No fix yet Fix from $1,9502023-04-11 HIGH 7.5 CVE-2022-43768 A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (Al… Simatic Cp 1242 7 V2 Firmware Mitigation only Fix from $1,9502023-04-11 HIGH 7.5 CVE-2023-27191 An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the SharedPreference files. Super Security No fix yet Fix from $1,9502023-04-11 HIGH 7.5 CVE-2023-24536 Multipart form parsing can consume large amounts of CPU and memory when processing form inputs containing very large numbers of parts. This stems fro… Go 1.19.8 / 1.20.3+ Fix from $1,9502023-04-06 MEDIUM 6.5 CVE-2023-0382 User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. M Files Server 23.4.12528.1+ Fix from $1,6002023-04-05 MEDIUM 6.5 CVE-2023-27492 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.26.0, 1.25.3, 1.24.4, 1.23.6, and 1.22.9, … Envoy 1.22.9 / 1.23.6+ Fix from $1,6002023-04-04 HIGH 7.5 CVE-2022-48357 Some products have the double fetch vulnerability. Successful exploitation of this vulnerability may cause denial of service (DoS) attacks to the ker… Emui No fix yet Fix from $1,9502023-03-27 MEDIUM 5.9 CVE-2022-46416 Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, th… Bebop Firmware Mitigation only Fix from $1,6002023-03-27 HIGH 7.5 CVE-2023-28867 In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20… Graphql Java 17.5 / 18.4+ Fix from $1,9502023-03-27 MEDIUM 6.3 CVE-2023-1544 A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a… Fedora after 7.2.0 Fix from $1,6002023-03-23 MEDIUM 6.5 CVE-2023-20067 A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticate… Ios Xe Mitigation only Fix from $1,6002023-03-23 HIGH 7.5 CVE-2023-28119 The crewjam/saml go library contains a partial implementation of the SAML standard in golang. Prior to version 0.4.13, the package's use of `flate.Ne… Saml Patch available Fix from $1,9502023-03-22 HIGH 8.6 CVE-2022-42333 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c… Debian Linux after 4.17.0 Fix from $1,9502023-03-21 MEDIUM 6.5 CVE-2022-42334 x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities c… Debian Linux after 4.17.0 Fix from $1,6002023-03-21 HIGH 7.5 CVE-2021-46877 jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usag… Jackson Databind 2.12.6+ Fix from $1,9502023-03-18 HIGH 7.5 CVE-2023-28104 `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted gr… Graphql Patch available Fix from $1,9502023-03-16 HIGH 7.5 CVE-2023-28338 Any request send to a Netgear Nighthawk Wifi6 Router (RAX30)'s web service containing a “Content-Type” of “multipartboundary=” will result in the req… Rax30 Firmware Mitigation only Fix from $1,9502023-03-15 HIGH 7.5 CVE-2023-27596 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.8 and 3.2.5, OpenSIPS crashes when a malformed SDP body … Opensips 3.1.8 / 3.2.5+ Fix from $1,9502023-03-15 HIGH 7.5 CVE-2023-27530 A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an at… Rack 2.0.9.3 / 2.1.4.3+ Fix from $1,9502023-03-10 HIGH 7.5 CVE-2023-27900 Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request par… Jenkins 2.375.4 / 2.394+ Fix from $1,9502023-03-10 HIGH 7.5 CVE-2023-27901 Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request par… Jenkins 2.375.4 / 2.394+ Fix from $1,9502023-03-10 HIGH 7.5 CVE-2022-41725 A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader… Go 1.19.6+ Fix from $1,9502023-02-28