Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-32588
Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users …
Cassandra
4.0.20 / 4.1.11+
MEDIUM 6.5
CVE-2026-35441
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql…
Directus
11.17.0+
HIGH 7.5
CVE-2025-54324
An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1…
Exynos 990 Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-58349
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 14…
Exynos 990 Firmware
Mitigation only
MEDIUM 6.2
CVE-2026-0049
In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local …
Android
Mitigation only
HIGH 7.5
CVE-2025-59440
An issue was discovered in USIM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, …
Exynos 990 Firmware
Mitigation only
HIGH 7.5
CVE-2026-34148
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify fo…
Fedify\/fedify
1.9.6 / 1.10.5+
HIGH 7.5
CVE-2022-4986
Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establ…
Eaglesdv Firmware
05.4.02+
HIGH 7.5
CVE-2024-14033
Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. Attackers can crash the device…
Mitigation only
HIGH 7.5
CVE-2026-34827
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mi…
Rack
3.1.21 / 3.2.6+
HIGH 7.5
CVE-2026-34593
Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 uncondit…
Ash Framework
3.22.0+
HIGH 7.5
CVE-2026-34829
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a Bo…
Rack
2.2.23 / 3.1.21+
HIGH 7.5
CVE-2026-34826
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header wi…
Rack
2.2.23 / 3.1.21+
HIGH 7.5
CVE-2026-34230
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding …
Rack
2.2.23 / 3.1.21+
HIGH 7.5
CVE-2026-31935
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exh…
Suricata
7.0.15 / 8.0.4+
MEDIUM 6.5
CVE-2026-5316
A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation…
Stb Vorbis.c
after 1.22
HIGH 7.5
CVE-2026-22815
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer …
Aiohttp
3.13.4+
HIGH 8.6
CVE-2026-34445
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in…
Onnx
1.21.0+
HIGH 7.5
CVE-2026-34404
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by the URI: /_og/d/ (and, in old…
Og Image
6.2.5+
HIGH 7.5
CVE-2026-34043
Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS…
Serialize
7.0.5+
HIGH 7.5
CVE-2026-33750
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, 3.0.2, 2.0.3, and 1.1.13, a b…
Brace Expansion
1.1.13 / 2.0.3+
MEDIUM 6.5
CVE-2026-27879
A resample query can be used to trigger out-of-memory crashes in Grafana.
Grafana
8.0.0 / 12.0.0+
MEDIUM 6.5
CVE-2026-28375
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
Grafana
8.1.0 / 12.0.0+
HIGH 7.5
CVE-2026-27858
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
Attacker can for…
Dovecot
2.3.22.1 / 2.4.3+
MEDIUM 5.3
CVE-2026-27859
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail…
Dovecot
2.4.3 / 3.0.5+
HIGH 7.5
CVE-2026-27857
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnec…
Dovecot
2.3.22.1 / 2.4.3+
HIGH 7.2
CVE-2026-33623
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a Windows-only command inj…
Pinchtab
0.8.5+
MEDIUM 6.5
CVE-2026-33375
The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catast…
Grafana
11.6.14 / 12.1.10+
MEDIUM 6.5
CVE-2026-33541
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparenc…
Tsportal
34+
HIGH 7.5
CVE-2026-4926
Impact:
A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The…
Path To Regexp
8.4.0+