Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2026-50722
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the I…
Libreswan
5.3.1+
HIGH 7.5
CVE-2026-12413
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service.…
Libreswan
5.3.1+
MEDIUM 5.5
CVE-2026-53319
In the Linux kernel, the following vulnerability has been resolved:
blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()
wbt_init_enable_def…
Linux Kernel
7.0.10+
MEDIUM 5.5
CVE-2026-53292
In the Linux kernel, the following vulnerability has been resolved:
net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind
syzbot repo…
Linux Kernel
7.0.10+
MEDIUM 5.5
CVE-2026-53285
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_E…
Linux Kernel
7.0.10+
MEDIUM 6.5
CVE-2026-9718
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting syste…
Powerlogic P7 Firmware
02.004.001.000+
MEDIUM 6.5
CVE-2026-47145
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a dev…
Emberznet
after 9.0.2
MEDIUM 6.5
CVE-2026-47146
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a dev…
Emberznet
after 9.0.2
MEDIUM 5.5
CVE-2026-53169
In the Linux kernel, the following vulnerability has been resolved:
accel/ethosu: reject NPU_OP_RESIZE commands from userspace
NPU_OP_RESIZE is a U…
Linux Kernel
7.0.13+
MEDIUM 5.5
CVE-2026-53039
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: validate group add input before caching
[BUG]
OCFS2_IOC_GROUP_ADD can tr…
Linux Kernel
5.10.258 / 5.15.209+
MEDIUM 5.5
CVE-2026-52961
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
The gener…
Linux Kernel
6.12.91 / 6.18.33+
HIGH 8.8
CVE-2026-52952
In the Linux kernel, the following vulnerability has been resolved:
iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
In __iommu…
Linux Kernel
7.0.10+
HIGH 7.5
CVE-2026-52954
In the Linux kernel, the following vulnerability has been resolved:
libceph: handle rbtree insertion error in decode_choose_args()
A message of typ…
Linux Kernel
5.10.258 / 5.15.209+
MEDIUM 6.5
CVE-2026-10651
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte a…
Zephyr
after 4.4.1
HIGH 7.5
CVE-2026-41523
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation functi…
Vllm
0.22.0+
MEDIUM 6.5
CVE-2026-52718
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function pas…
Mitigation only
MEDIUM 6.9
CVE-2026-29115
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an …
Mitigation only
HIGH 8.7
CVE-2026-29116
A vulnerability has been found in some Dahua products could
allow an unauthenticated remote attacker to send a specially crafted packet,
triggering a…
Mitigation only
MEDIUM 5.3
CVE-2026-46543
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer…
Patch available
MEDIUM 6.5
CVE-2026-9747
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
MongoDB
7.0.35 / 8.0.24+
MEDIUM 6.5
CVE-2026-9748
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But Pa…
MongoDB
7.0.35 / 8.0.10+
MEDIUM 6.5
CVE-2026-9749
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-pre…
MongoDB
7.0.35 / 8.0.24+
MEDIUM 6.5
CVE-2026-9750
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata pro…
MongoDB
7.0.35 / 8.0.24+
MEDIUM 6.5
CVE-2026-9746
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. …
MongoDB
7.0.35 / 8.0.24+
MEDIUM 6.5
CVE-2026-35058
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authentic…
Openvpn
2.6.20 / 2.7.2+
MEDIUM 5.5
CVE-2026-46287
In the Linux kernel, the following vulnerability has been resolved:
net: txgbe: fix RTNL assertion warning when remove module
For the copper NIC wi…
Linux Kernel
6.6.140 / 6.12.88+
HIGH 7.5
CVE-2026-37228
FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and …
Flexric
No fix yet
HIGH 7.5
CVE-2026-37229
FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote unauthenticated attacker can sen…
Flexric
No fix yet
HIGH 7.5
CVE-2026-37233
FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xa…
Flexric
No fix yet
HIGH 7.5
CVE-2026-37222
FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote unauthenticated attacker can …
Mitigation only