Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2022-41727
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a deni…
Image
0.5.0+
MEDIUM 6.5
CVE-2023-23916
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, mea…
Curl
7.88.0+
HIGH 7.5
CVE-2022-31394
Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers …
Hyper
0.14.19+
HIGH 7.5
CVE-2023-26249
Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. S…
Knot Resolver
5.6.0+
HIGH 7.5
CVE-2021-32848
Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted searc…
Octobox
2021-11-02+
HIGH 7.5
CVE-2023-24998EPSS 47%
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggerin…
Commons Fileupload
1.5+
HIGH 7.5
CVE-2023-25656
notation-go is a collection of libraries for supporting Notation sign, verify, push, and pull of oci artifacts. Prior to version 1.0.0-rc.3, notation…
Notation Go
Mitigation only
MEDIUM 5.5
CVE-2023-24785
An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA fea…
Peazip
No fix yet
MEDIUM 5.5
CVE-2023-25153
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of b…
Containerd
1.5.18 / 1.6.18+
HIGH 8.1
CVE-2023-0568
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolv…
PHP
8.0.28 / 8.1.16+
CRITICAL 9.8
CVE-2023-25156
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force …
Kiwi Tcms
12.0+
MEDIUM 5.9
CVE-2023-25171
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-se…
Kiwi Tcms
12.0+
HIGH 7.5
CVE-2023-25578
Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing in `starlite` allows a potent…
Starlite
1.51.2+
HIGH 7.5
CVE-2023-25577
Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited numbe…
Werkzeug
2.2.3+
HIGH 7.5
CVE-2023-25576
@fastify/multipart is a Fastify plugin to parse the multipart content-type. Prior to versions 7.4.1 and 6.0.1, @fastify/multipart may experience deni…
Fastify Multipart
6.0.1 / 7.4.1+
HIGH 7.5
CVE-2023-25193
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back…
Fedora
after 6.0.0
HIGH 7.5
CVE-2023-23969EPSS 47%
In Django 3.2 before 3.2.17, 4.0 before 4.0.9, and 4.1 before 4.1.6, the parsed values of Accept-Language headers are cached in order to avoid repeti…
Django
3.2.17 / 4.0.9+
HIGH 7.5
CVE-2023-22323
In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when O…
Big Ip Access Policy Manager
14.1.5.3 / 15.1.8.1+
HIGH 7.5
CVE-2023-23846
Due to insufficient length validation in the Open5GS GTP library versions prior to versions 2.4.13 and 2.5.7, when parsing extension headers in GPRS …
Open5gs
2.4.13+
MEDIUM 6.5
CVE-2023-22740
Discourse is an open source platform for community discussion. Versions prior to 3.1.0.beta1 (beta) (tests-passed) are vulnerable to Allocation of R…
Discourse
after 3.0.0
MEDIUM 6.5
CVE-2023-22739
Discourse is an open source platform for community discussion. Versions prior to 3.0.1 (stable), 3.1.0.beta2 (beta), and 3.1.0.beta2 (tests-passed) a…
Discourse
3.0.1+
MEDIUM 5.5
CVE-2022-20494
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of servi…
Android
Mitigation only
HIGH 7.8
CVE-2022-20489
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead t…
Android
Mitigation only
HIGH 7.8
CVE-2022-20490
In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could le…
Android
Mitigation only
HIGH 7.8
CVE-2022-20492
In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead t…
Android
Mitigation only
HIGH 7.8
CVE-2022-20456
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead…
Android
Mitigation only
MEDIUM 6.5
CVE-2023-20047
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco Webex Room Phone and Cisco Webex Share devices could allow an unauthenti…
Webex Room Phone Firmware
after 1.2.0
HIGH 7.5
CVE-2021-36630
DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote attackers to perform DOS attack…
Sz 300 Firmware
after 3.6.2
MEDIUM 6.1
CVE-2023-22397
An Allocation of Resources Without Limits or Throttling weakness in the memory management of the Packet Forwarding Engine (PFE) on Juniper Networks J…
Junos Os Evolved
20.4+
HIGH 7.5
CVE-2023-22403
An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a net…
Junos
20.2+