Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-52829
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node usin…
Fix unknown
MEDIUM 6.5
CVE-2026-43667
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privilege…
Ipados
Fix unknown
MEDIUM 5.3
CVE-2025-15684
A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/common/init.c of the component C…
No fix yet
MEDIUM 6.5
CVE-2026-18695
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user …
No fix yet
HIGH 7.5
CVE-2026-18697
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly …
No fix yet
MEDIUM 6.2
CVE-2026-71430
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result…
No fix yet
HIGH 7.5
CVE-2026-52856
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received dur…
No fix yet
MEDIUM 5.9
CVE-2026-66754
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated at…
No fix yet
MEDIUM 5.5
CVE-2026-17574
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length dataty…
Hdf5
No fix yet
MEDIUM 5.5
CVE-2026-64254
In the Linux kernel, the following vulnerability has been resolved:
NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
W…
Linux Kernel
6.1.177 / 6.6.144+
HIGH 7.5
CVE-2026-45815
Reachable Assertion vulnerability in Apache NimBLE.
A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigge…
Nimble
1.10.0+
MEDIUM 6.5
CVE-2026-9737
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may…
No fix yet
MEDIUM 6.5
CVE-2026-13055
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to han…
MongoDB
7.0.39 / 8.0.28+
MEDIUM 6.5
CVE-2026-13058
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with …
MongoDB
8.0.28 / 8.2.12+
HIGH 7.5
CVE-2026-13204
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B…
No fix yet
MEDIUM 6.5
CVE-2026-10822
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.
BIND w…
No fix yet
HIGH 7.5
CVE-2026-12617
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Spec…
No fix yet
MEDIUM 5.9
CVE-2026-14586
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in lib…
No fix yet
MEDIUM 5.5
CVE-2026-10674
The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, called LPUART_Deinit() at the st…
Zephyr
after 4.4.1
MEDIUM 6.5
CVE-2026-63140
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search requ…
Elasticsearch
8.19.19 / 9.3.8+
HIGH 7.1
CVE-2026-63806
In the Linux kernel, the following vulnerability has been resolved:
KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligne…
Linux Kernel
5.10.261 / 5.15.212+
HIGH 7.5
CVE-2026-44435
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure i…
Quicly
2026-05-29+
HIGH 7.5
CVE-2025-56362
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic…
Matter
Mitigation only
HIGH 7.5
CVE-2025-56365
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When …
Matter
1.4.0.0+
HIGH 7.5
CVE-2025-56361
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server t…
Matter
Mitigation only
MEDIUM 6.2
CVE-2026-47475
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the samp…
Mitigation only
MEDIUM 6.1
CVE-2026-58307
Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation.
This issue a…
Patch available
MEDIUM 6.5
CVE-2026-55514
vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with…
Vllm
0.24.0+
MEDIUM 5.3
CVE-2026-13122
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication…
Openvpn
2.6.21 / 2.7.5+
MEDIUM 5.9
CVE-2026-50721
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG pa…
Libreswan
5.3.1+