Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.9
CVE-2026-53423
Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service …
Patch available
HIGH 7.5
CVE-2026-5497
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the …
Vllm
0.19.0+
HIGH 7.5
CVE-2026-53460
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing ch…
Imagemagick
6.9.13-50 / 7.1.2-25+
HIGH 7.5
CVE-2026-46673
Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsa…
Mitigation only
HIGH 7.5
CVE-2026-46702
Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabled, russh accepted compressed…
No fix yet
MEDIUM 5.3
CVE-2026-45664
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a…
Imagemagick
6.9.13-47 / 7.1.2-22+
MEDIUM 5.3
CVE-2026-45031
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a mis…
Imagemagick
6.9.13-47 / 7.1.2-22+
MEDIUM 5.3
CVE-2026-10740
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of s…
Mitigation only
MEDIUM 6.5
CVE-2026-24720
An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a…
File Station
5.5.6.5243+
MEDIUM 6.5
CVE-2026-41726
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spr…
Spring For Apache Kafka
2.8.12 / 2.9.14+
HIGH 7.5
CVE-2026-41716
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion throug…
Spring Data Commons
2.7.20 / 3.3.17+
MEDIUM 5.5
CVE-2026-28237
Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability.
Uprof
5.3.518+
MEDIUM 5.3
CVE-2026-49955
Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service ava…
Patch available
HIGH 7.5
CVE-2026-45591
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Asp.net Core
8.0.28 / 9.0.17+
HIGH 7.5
CVE-2026-42570
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to be…
Devalue
5.8.1+
HIGH 7.5
CVE-2026-41851
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the ev…
Spring Framework
5.3.49 / 6.1.28+
HIGH 7.5
CVE-2026-41007
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.
Affected versions:
Spring HAT…
Spring Hateoas
1.5.7 / 2.3.5+
MEDIUM 5.9
CVE-2026-41710
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache.…
No fix yet
HIGH 7.5
CVE-2026-40983
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.
Affected ver…
Mitigation only
HIGH 7.5
CVE-2026-40984
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Affected ver…
Mitigation only
HIGH 7.5
CVE-2026-43973
Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded H…
Gun
Patch available
HIGH 7.5
CVE-2026-45290
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` i…
Mitigation only
HIGH 7.5
CVE-2026-50589
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC s…
Ironic
37.0.0+
MEDIUM 6.5
CVE-2026-36499
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an exce…
Mitigation only
HIGH 7.5
CVE-2026-40898
quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP…
Quic Go
0.59.1+
HIGH 7.5
CVE-2025-46638
Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially…
Mitigation only
HIGH 7.5
CVE-2026-44545
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both va…
Daphne
4.2.2+
MEDIUM 5.9
CVE-2026-48597
Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.…
Tesla
Patch available
HIGH 7.5
CVE-2026-34077
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is…
React Router
3.0.0 / 7.14.0+
HIGH 7.5
CVE-2026-28299
SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to …
Web Help Desk
2026.2+