Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-42304
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to …
Twisted
26.4.0+
MEDIUM 6.5
CVE-2026-33378
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-resta…
Grafana
11.6.14 / 12.2.8+
HIGH 7.5
CVE-2026-44248
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section i…
Netty
4.1.133 / 4.2.13+
HIGH 7.5
CVE-2026-42587
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxA…
Netty
4.1.133 / 4.2.13+
CRITICAL 9.1
CVE-2026-42579
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC…
Netty
4.1.133 / 4.2.13+
HIGH 7.5
CVE-2026-42583
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Lz4FrameDecoder allocates a ByteBuf of…
Netty
4.1.133 / 4.2.13+
MEDIUM 6.5
CVE-2026-44456
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize…
Hono
4.12.16+
HIGH 7.5
CVE-2026-44296
Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow s…
Patch available
HIGH 7.5
CVE-2026-44241
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. From 4.3.0 to before 4.…
Patch available
HIGH 7.5
CVE-2026-42544
Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a We…
Mitigation only
HIGH 7.5
CVE-2026-44240
basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel mul…
Mitigation only
MEDIUM 6.2
CVE-2026-34677
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou…
C2pa
0.7.1 / 0.80.1+
MEDIUM 6.2
CVE-2026-34678
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou…
C2pa
0.7.1 / 0.80.1+
HIGH 7.5
CVE-2026-34665
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou…
C2pa
0.7.1 / 0.80.1+
MEDIUM 6.2
CVE-2026-34673
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that cou…
C2pa
0.7.1 / 0.80.1+
HIGH 7.5
CVE-2026-34650EPSS 16%
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump…
Commerce
1.3.3 / 2.4.4+
HIGH 7.5
CVE-2026-34651
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump…
Commerce
1.3.3 / 2.4.4+
HIGH 7.5
CVE-2026-34648EPSS 23%
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump…
Commerce
1.3.3 / 2.4.4+
HIGH 7.5
CVE-2026-34649EPSS 14%
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consump…
Commerce
1.3.3 / 2.4.4+
HIGH 7.5
CVE-2026-23824
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnera…
Arubaos
8.10.0.22 / 8.12.0.7+
HIGH 7.5
CVE-2026-44167
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RS…
Patch available
MEDIUM 6.5
CVE-2026-40016
Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of …
Dovecot
2.4.4 / 3.1.5+
MEDIUM 6.2
CVE-2026-43653
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 1…
Ipados
14.8.7 / 18.7.9+
HIGH 7.5
CVE-2026-28908
A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Taho…
macOS
14.8.7 / 15.7.7+
HIGH 7.5
CVE-2026-28872
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26…
Ipados
18.7.9 / 26.4+
MEDIUM 5.3
CVE-2026-8319
A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_rel…
Mitigation only
HIGH 7.5
CVE-2026-7790
Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation.
The chunked transfer-encoding …
Cowlib
2.16.1+
HIGH 7.5
CVE-2026-31247
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without…
Mitigation only
HIGH 8.6
CVE-2025-10470
The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to un…
Identity Server
7.0.0.121+
HIGH 7.5
CVE-2026-8187
A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executi…
Open5gs
after 2.7.7