Skip to main content

CWE archive

CWE-1333 CVEs

Programmatic archive

455 CVEs tagged with CWE-13335 Critical, 217 High, 195 Medium, 37 Low, 1 Unrated.

CVE-2024-4067

Published May 14, 2024

The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2651

Published May 14, 2024

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6688

Published May 14, 2024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6682

Published May 14, 2024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.1…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28716

Published Apr 30, 2024

An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

CVSS 7.5 · High

CVE-2024-4056

Published Apr 26, 2024

Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2829

Published Apr 25, 2024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 1…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-6678

Published Apr 12, 2024

An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6489

Published Apr 12, 2024

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spik…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22363

Published Apr 5, 2024

SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).

CVSS 7.5 · High

CVE-2024-21503

Published Mar 19, 2024

Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file…

CVSS 5.3 · Medium

CVE-2024-28865

Published Mar 18, 2024

django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciously crafted article content that can cause severe use of se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28864

Published Mar 18, 2024

SecureProps is a PHP library designed to simplify the encryption and decryption of property data in objects. A vulnerability in SecureProps version 1.2.0 and 1.2.1 involves a rege…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-27351

Published Mar 15, 2024

In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (with html=True) and the truncatewords_html template filter ar…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26146

Published Feb 29, 2024

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a possible denial of service issu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25126

Published Feb 29, 2024

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible den…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1892

Published Feb 28, 2024

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy project, specifically in the parsing of XML content. By craftin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26142

Published Feb 27, 2024

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerabili…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27088

Published Feb 26, 2024

es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2023-51931

Published Feb 16, 2024

An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-4437

Published Feb 12, 2024

A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-21490

Published Feb 10, 2024

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6736

Published Feb 7, 2024

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 b…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 455 CVEsPage 10 of 19