Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-59941
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared …
Dompdf
3.1.6+
HIGH 7.5
CVE-2026-59942
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An at…
Dompdf
3.1.6+
HIGH 7.5
CVE-2026-14981
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of se…
Websphere Application Server
8.5.5.31 / 9.0.5.29+
HIGH 7.5
CVE-2026-59932
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …
No fix yet
HIGH 7.5
CVE-2026-59933
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …
No fix yet
HIGH 8.6
CVE-2026-54609
QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards REC…
No fix yet
HIGH 7.5
CVE-2026-66299
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through…
Tomcat
9.0.121 / 10.1.58+
HIGH 8.2
CVE-2026-66920
Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursiv…
No fix yet
MEDIUM 6.9
CVE-2026-66913
Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files.
An attacker could submit a specially…
No fix yet
HIGH 7.5
CVE-2026-42493
Addressing certain issues, in particular related to operations which may
take excessively long and therefore would need preemption, has turned out
ov…
No fix yet
HIGH 7.5
CVE-2025-63913
An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and co…
No fix yet
HIGH 7.5
CVE-2026-55685
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests t…
React Router
7.18.0+
MEDIUM 5.5
CVE-2026-64724
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia…
Ipados
14.8.8 / 15.7.8+
MEDIUM 6.5
CVE-2026-43804
This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS …
Safari
26.6+
MEDIUM 5.5
CVE-2026-43806
A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cau…
macOS
26.6+
MEDIUM 5.5
CVE-2026-43768
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may…
macOS
14.8.8 / 15.7.8+
MEDIUM 5.5
CVE-2026-28932
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8,…
macOS
14.8.8 / 15.7.8+
MEDIUM 5.3
CVE-2026-17501
A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp …
No fix yet
HIGH 7.5
CVE-2026-66142
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to …
Neethi
3.2.3+
HIGH 7.5
CVE-2026-66143
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies…
Neethi
No fix yet
HIGH 7.5
CVE-2026-66144
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of …
Neethi
3.2.3+
HIGH 7.5
CVE-2026-14257
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max…
No fix yet
MEDIUM 5.3
CVE-2026-21723
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-e…
No fix yet
MEDIUM 5.5
CVE-2026-38763
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828
No fix yet
MEDIUM 6.6
CVE-2026-45820
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry dec…
No fix yet
MEDIUM 6.5
CVE-2026-63263
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticat…
Elasticsearch
8.19.19 / 9.3.8+
MEDIUM 6.5
CVE-2026-63260
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker w…
Kibana
8.19.19 / 9.3.8+
MEDIUM 6.5
CVE-2026-63261
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authentica…
Kibana
8.19.19 / 9.3.8+
HIGH 7.5
CVE-2026-56819
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Fina…
Netty
4.1.136 / 4.2.16+
HIGH 7.6
CVE-2026-62518
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are a…
E Business Suite
after 12.2.15