Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-54283
Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource cons…
Starlette
1.3.1+
MEDIUM 5.3
CVE-2026-54270
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unknown wire elements in message.$…
Protobufjs
8.5.0+
HIGH 7.5
CVE-2026-54273
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requ…
Aiohttp
3.14.1+
HIGH 7.5
CVE-2026-54274
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket fram…
Aiohttp
3.14.1+
HIGH 7.5
CVE-2026-42127
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memor…
Grafana
after 13.0.1
MEDIUM 6.5
CVE-2024-54178
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denia…
Db2
5.4+
HIGH 8.6
CVE-2025-7737
DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform.
This issue affects Hitachi Virtual Storage Platform E990, E1090, E10…
Mitigation only
MEDIUM 5.3
CVE-2026-55205
Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allow…
Patch available
MEDIUM 5.3
CVE-2026-48990
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through…
No fix yet
HIGH 7.5
CVE-2026-47774
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulne…
Openshift Service Mesh
1.35.11 / 1.36.7+
HIGH 7.5
CVE-2026-9675
Impact:
The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A…
Undici
8.5.0+
HIGH 7.5
CVE-2026-12151
Impact:
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on th…
Undici
6.27.0 / 7.28.0+
HIGH 7.5
CVE-2026-48779
ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7…
Ws
5.2.5 / 6.2.4+
MEDIUM 6.9
CVE-2026-27869
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the…
Mitigation only
CRITICAL 9.2
CVE-2026-48853
Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated …
Patch available
HIGH 8.7
CVE-2026-48854
Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory …
Patch available
MEDIUM 6.5
CVE-2026-8683
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows …
Mattermost Desktop
after 6.1.5
MEDIUM 6.5
CVE-2026-53522
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the Nezha…
Mitigation only
MEDIUM 5.3
CVE-2026-50560
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty HTT…
Netty
4.1.135 / 4.2.15+
HIGH 7.5
CVE-2026-50011
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, RedisArra…
Netty
4.1.135 / 4.2.15+
HIGH 7.5
CVE-2026-48748
Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Final and prior to version 4.2.15…
Netty
4.2.15+
HIGH 7.5
CVE-2026-46340
Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final …
Netty
4.1.135 / 4.2.15+
HIGH 7.5
CVE-2026-45416
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClient…
Netty
4.1.135 / 4.2.15+
MEDIUM 5.3
CVE-2026-49347
Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly create new ticket channels. T…
Mitigation only
HIGH 7.5
CVE-2026-44250
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.…
Netty
4.1.135 / 4.2.15+
HIGH 7.5
CVE-2026-44890
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.…
Netty
4.1.135 / 4.2.15+
MEDIUM 6.0
CVE-2026-45802
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2…
Patch available
HIGH 7.5
CVE-2026-44488
Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response…
Axios
1.16.0+
HIGH 7.5
CVE-2026-7250
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un…
GitLab
18.10.8 / 18.11.5+
MEDIUM 6.5
CVE-2026-1500
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that un…
GitLab
18.10.8 / 18.11.5+