Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-34063
Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `Connectio…
Nimiq Proof Of Stake
1.3.0+
MEDIUM 5.5
CVE-2026-31451
In the Linux kernel, the following vulnerability has been resolved:
ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio
Repla…
Linux Kernel
6.6.131 / 6.12.80+
MEDIUM 5.3
CVE-2026-34069
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 a…
Nimiq Proof Of Stake
1.3.0+
MEDIUM 5.5
CVE-2026-31415
In the Linux kernel, the following vulnerability has been resolved:
ipv6: avoid overflows in ip6_datagram_send_ctl()
Yiming Qian reported :
<quote>…
Linux Kernel
5.10.253 / 5.15.203+
MEDIUM 5.5
CVE-2026-34933
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileg…
Avahi
0.9+
HIGH 7.8
CVE-2026-31398
In the Linux kernel, the following vulnerability has been resolved:
mm/rmap: fix incorrect pte restoration for lazyfree folios
We batch unmap anony…
Linux Kernel
6.18.20 / 6.19.10+
MEDIUM 6.5
CVE-2026-30867
CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic…
Cocoamqtt
2.2.2+
MEDIUM 5.9
CVE-2026-34219
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implement…
Libp2p Gossipsub
0.49.4+
MEDIUM 6.5
CVE-2026-33977
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can crash the FreeRDP client by send…
Freerdp
3.24.2+
MEDIUM 6.5
CVE-2026-33952
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length field read from the network trig…
Freerdp
3.24.2+
HIGH 7.5
CVE-2026-4046
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or …
Glibc
after 2.43
MEDIUM 5.3
CVE-2026-5170
A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during the limited and unpredictabl…
MongoDB
7.0.31 / 8.0.18+
MEDIUM 6.5
CVE-2026-3119
Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached …
Bind
9.20.21 / 9.21.20+
MEDIUM 5.5
CVE-2026-23380
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix WARN_ON in tracing_buffers_mmap_close
When a process forks, the ch…
Linux Kernel
6.12.77 / 6.18.17+
MEDIUM 5.5
CVE-2026-23375
In the Linux kernel, the following vulnerability has been resolved:
mm: thp: deny THP for files on anonymous inodes
file_thp_enabled() incorrectly …
Linux Kernel
6.12.78 / 6.18.17+
MEDIUM 5.5
CVE-2026-23356
In the Linux kernel, the following vulnerability has been resolved:
drbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
Even though we check that …
Linux Kernel
5.10.253 / 5.15.203+
HIGH 7.5
CVE-2026-3608
Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA list…
Mitigation only
HIGH 7.1
CVE-2026-23555
Any guest issuing a Xenstore command accessing a node using the
(illegal) node path "/local/domain/", will crash xenstored due to a
clobbered error i…
Xen
Patch available
HIGH 7.5
CVE-2026-27135
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incomi…
Nghttp2
1.68.1+
MEDIUM 6.5
CVE-2025-69653
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb…
Quickjs
2025-12-11+
HIGH 7.5
CVE-2025-69534
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled Assert…
Markdown
No fix yet
MEDIUM 5.5
CVE-2026-23238
In the Linux kernel, the following vulnerability has been resolved:
romfs: check sb_set_blocksize() return value
romfs_fill_super() ignores the ret…
Linux Kernel
5.10.251 / 5.15.201+
MEDIUM 6.5
CVE-2025-47384
Transient DOS when MAC configures config id greater than supported maximum value.
5g Fixed Wireless Access Platform Firmware
No fix yet
MEDIUM 6.5
CVE-2025-47371
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
5g Fixed Wireless Access Platform Firmware
Mitigation only
CRITICAL 9.1
CVE-2026-27809
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed …
Psd Tools
1.12.2+
MEDIUM 6.5
CVE-2026-27015
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align…
Freerdp
3.23.0+
HIGH 7.5
CVE-2026-27623
Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can…
Valkey
9.0.3+
HIGH 7.5
CVE-2026-2523
A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_context_request of the file /src/s…
Open5gs
after 2.7.6
MEDIUM 6.5
CVE-2025-48023
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation.
If affected product receives maliciously craft…
Vnet\/ip Interface Package
Mitigation only
MEDIUM 6.5
CVE-2025-48019
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation.
If affected product receives maliciously craft…
Vnet\/ip Interface Package
Mitigation only