Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-42402
Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documen…
Neethi
3.2.2+
MEDIUM 5.5
CVE-2026-40951
CVE-2026-40951 is a memory corruption vulnerability on Secure Access
Windows clients prior to 14.50. Attackers with local control of the
Windows cl…
Secure Access
14.50+
HIGH 7.5
CVE-2025-46115
An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request
Mitigation only
HIGH 7.5
CVE-2026-36957
Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating a high-…
Dbit N300 T1 Pro Firmware
No fix yet
HIGH 7.5
CVE-2026-36958
A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random …
N300 Firmware
No fix yet
HIGH 8.2
CVE-2026-28221
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-ba…
Wazuh
4.14.4+
MEDIUM 6.5
CVE-2026-22740
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files ma…
Spring Framework
5.3.48 / 6.1.27+
MEDIUM 5.3
CVE-2026-22745
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.
More precisely, an application can…
Spring Framework
5.3.48 / 6.1.27+
MEDIUM 6.5
CVE-2026-40980
In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextSt…
Spring Ai
1.0.6 / 1.1.5+
HIGH 7.5
CVE-2026-30350
An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via a crafted…
Mitigation only
HIGH 7.5
CVE-2026-41680
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a sp…
Marked
18.0.2+
MEDIUM 5.3
CVE-2026-31052
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout Authentication Flow component
No fix yet
HIGH 7.5
CVE-2026-21728
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment stra…
Tempo
2.8.4 / 2.9.2+
HIGH 7.5
CVE-2026-41324
basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing …
Basic Ftp
5.3.0+
HIGH 8.2
CVE-2026-41309
Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaus…
Patch available
HIGH 7.5
CVE-2026-33610
A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS updat…
Authoritative
4.9.14 / 5.0.4+
MEDIUM 5.5
CVE-2026-6844
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by prov…
Hardened Images
Mitigation only
HIGH 7.5
CVE-2026-6022
In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file up…
Telerik Ui For Asp.net Ajax
2026.1.421+
HIGH 8.7
CVE-2026-41146
facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_json_parse` can enter an infinit…
Patch available
HIGH 7.5
CVE-2026-41135
free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. A memory leak v…
Free5gc
1.4.3+
MEDIUM 6.5
CVE-2026-40924
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3…
Tekton Pipelines
1.11.1+
MEDIUM 6.5
CVE-2026-34308
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.…
Mysql Server
after 9.6.0
MEDIUM 6.5
CVE-2026-34303
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4…
Mysql Server
after 9.6.0
HIGH 7.5
CVE-2026-34290
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affecte…
Identity Manager Connector
Mitigation only
MEDIUM 6.5
CVE-2026-34281
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11.4. Easily exploitab…
Solaris
Mitigation only
HIGH 7.5
CVE-2026-34282
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Su…
Jre
Mitigation only
MEDIUM 6.5
CVE-2026-34272
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.0.0-9.6.0. Easi…
Mysql Server
after 9.6.0
MEDIUM 6.5
CVE-2026-34276
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.…
Mysql Server
after 9.6.0
MEDIUM 6.6
CVE-2026-34277
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected ar…
Peoplesoft Enterprise Peopletools
Mitigation only
MEDIUM 6.5
CVE-2026-34270
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.…
Mysql Server
after 9.6.0