Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
HIGH 7.5 CVE-2022-29404EPSS 6% In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no defau… HTTP Server after 2.4.53 Fix from $1,9502022-06-09 HIGH 7.5 CVE-2022-30522EPSS 90% If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may m… HTTP Server Mitigation only Fix from $1,9502022-06-09 HIGH 7.5 CVE-2022-1708 A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync reque… Cri O 1.19.7 / 1.20.8+ Fix from $1,9502022-06-07 MEDIUM 6.5 CVE-2022-29767 adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a Denial of Service (DoS) via h… Adbyby No fix yet Fix from $1,6002022-06-03 MEDIUM 5.5 CVE-2022-25169 The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. Tika 1.28.2 / 2.4.0+ Fix from $1,6002022-05-16 MEDIUM 5.5 CVE-2022-30775 xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a crafted PDF document to the … Xpdf No fix yet Fix from $1,6002022-05-16 MEDIUM 5.3 CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS att… Spring Framework after 5.3.19 Fix from $1,6002022-05-12 MEDIUM 6.5 CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable … Spring Framework after 5.3.19 Fix from $1,6002022-05-12 MEDIUM 5.5 CVE-2021-39670 In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation. This could lead to local de… Android Patch available Fix from $1,6002022-05-10 HIGH 7.5 CVE-2022-20751 A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote at… Secure Firewall Threat Defense 6.4.0.15 / 6.6.5.2+ Fix from $1,9502022-05-03 HIGH 7.5 CVE-2022-20757 A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker … Secure Firewall Threat Defense 6.4.0.15 / 6.6.5.2+ Fix from $1,9502022-05-03 HIGH 7.5 CVE-2022-20767 A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacke… Secure Firewall Threat Defense 7.0.2+ Fix from $1,9502022-05-03 HIGH 7.5 CVE-2022-22278 A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try t… Tz300p Firmware 7.0.1 / 7.0.1.0+ Fix from $1,9502022-04-27 HIGH 7.5 CVE-2022-29701 A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legiti… Zammad Patch available Fix from $1,9502022-04-27 HIGH 7.5 CVE-2022-28871 A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain F-Secure products while scann… Atlant Mitigation only Fix from $1,9502022-04-25 HIGH 7.5 CVE-2021-44502 An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a m… Gt.m after 7.0-000 Fix from $1,9502022-04-15 MEDIUM 5.5 CVE-2022-20717 A vulnerability in the NETCONF process of Cisco SD-WAN vEdge Routers could allow an authenticated, local attacker to cause an affected device to run … Sd Wan Vedge Router after 20.6 Fix from $1,6002022-04-15 HIGH 7.5 CVE-2022-20622 A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthe… Aironet Access Point Software 17.3.4 / 17.6.1+ Fix from $1,9502022-04-15 MEDIUM 6.5 CVE-2022-1333 Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allows authenticated and authorize… Playbooks after 1.24.0 Fix from $1,6002022-04-13 MEDIUM 6.5 CVE-2022-1337 The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied image, which allows an authentica… Mattermost Server 5.37.9 / 6.2.5+ Fix from $1,6002022-04-13 MEDIUM 5.3 CVE-2022-27819 SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of service (memory exhaustion) upon… Swhkd Patch available Fix from $1,6002022-04-07 MEDIUM 5.3 CVE-2022-1121 A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 … GitLab 14.7.7 / 14.8.5+ Fix from $1,6002022-04-04 MEDIUM 6.5 CVE-2022-22950EPSS 36% n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression t… Spring Framework 5.2.20 / 5.3.17+ Fix from $1,6002022-04-01 MEDIUM 6.5 CVE-2022-22404 IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.1, 3.0, and 3.1) may be vulne… App Connect Enterprise Certified Container 4.0.0+ Fix from $1,6002022-04-01 MEDIUM 6.5 CVE-2021-43662 totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontrolled resource consumption. Ex300 V2 Firmware No fix yet Fix from $1,6002022-03-31 HIGH 7.5 CVE-2017-20016 A vulnerability has been found in WEKA INTEREST Security Scanner up to 1.8 and classified as problematic. This vulnerability affects unknown code of … Interest Security Scanner after 1.8 Fix from $1,9502022-03-28 HIGH 7.5 CVE-2022-21822 NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Thr… Federated Learning Application Runtime Environment 2.0.16+ Fix from $1,9502022-03-17 HIGH 7.5 CVE-2021-32476 A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodle versions 3.10 to 3.10.3, 3.… Moodle 3.5.18 / 3.8.9+ Fix from $1,9502022-03-11 MEDIUM 6.5 CVE-2022-24741 Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uplo… Nextcloud Server 21.0.8 / 22.2.4+ Fix from $1,6002022-03-09 MEDIUM 5.5 CVE-2022-26336 A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read… Poi 5.2.1+ Fix from $1,6002022-03-04