Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.1
CVE-2026-44931
The newly introduced RecordUsage D-Bus method https://gitlab.freedesktop.org/pwithnall/malcontent/-/blob/0.14.0/libmalcontent-timer/child-timer-serv…
Mitigation only
MEDIUM 6.5
CVE-2026-8202
Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user w…
MongoDB
7.0.34 / 8.0.23+
HIGH 7.5
CVE-2026-40863
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML …
Phpspreadsheet
1.30.4 / 2.1.16+
HIGH 7.5
CVE-2026-40902
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's …
Phpspreadsheet
1.30.4 / 2.1.16+
HIGH 7.5
CVE-2026-44240
basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel mul…
Mitigation only
MEDIUM 5.5
CVE-2026-42444
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists in the littlefs filesystem ima…
Nanazip
6.0.1698.0+
HIGH 7.5
CVE-2026-23826
A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerabilit…
Arubaos
8.10.0.22 / 8.12.0.7+
HIGH 7.5
CVE-2026-41284
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2…
Tomcat
9.0.118 / 10.1.55+
HIGH 7.5
CVE-2026-22925
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to resource exhaustion when sub…
Simatic Cn 4100 Firmware
5.0+
MEDIUM 6.5
CVE-2026-42256
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.…
Net\
0.4.24 / 0.5.14+
HIGH 7.5
CVE-2026-42294
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, …
Argo Workflows
3.7.14 / 4.0.5+
HIGH 7.5
CVE-2026-42189
Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerability exists in the server's key…
Russh
0.23.1 / 0.60.1+
HIGH 8.7
CVE-2026-44499
ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeli…
Mitigation only
HIGH 7.5
CVE-2026-42793
Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service via atom tab…
Absinthe
1.10.2+
MEDIUM 5.3
CVE-2026-44500
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version…
Zebra Chain
4.4.0 / 6.0.0+
HIGH 7.8
CVE-2026-43329
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: strictly check for maximum number of actions
The maximum …
Linux Kernel
5.15.203 / 6.1.168+
MEDIUM 5.3
CVE-2025-69233
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of t…
Cloudstack
4.20.3.0 / 4.22.0.1+
MEDIUM 5.5
CVE-2026-8124
A security vulnerability has been detected in GPAC up to 26.02.0. This affects the function sidx_box_read of the file src/isomedia/box_code_base.c. T…
Gpac
after 26.02.0
HIGH 7.5
CVE-2026-7541
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by …
Enterprise Server
3.16.18 / 3.17.15+
HIGH 7.5
CVE-2026-39820
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
Go
1.25.10 / 1.26.3+
MEDIUM 5.0
CVE-2026-41648
Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML f…
Incus
7.0.0+
HIGH 8.3
CVE-2025-14341
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in…
Mitigation only
HIGH 7.1
CVE-2026-41644
monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) vulnerability in monetr's Lun…
Monetr
1.12.5+
MEDIUM 5.9
CVE-2026-41484
OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, whe…
Opentelemetry.exporter.onecollector
after 1.15.0
MEDIUM 5.3
CVE-2026-41310
OpenTelemetry.Exporter.Zipkin is the .NET Zipkin exporter for OpenTelemetry. In versions 1.15.2 and earlier, the Zipkin exporter remote endpoint cach…
Opentelemetry.exporter.zipkin
1.15.3+
MEDIUM 5.9
CVE-2026-41483
OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequest…
Opentelemetry.resources.azure
after 1.15.0
MEDIUM 5.3
CVE-2026-6860
A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if…
Vert.x
after 5.0.11
HIGH 7.5
CVE-2026-32934
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and m…
Coredns
1.14.3+
HIGH 8.7
CVE-2026-32689
Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport…
Patch available
HIGH 7.5
CVE-2025-66369
An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 24…
Mitigation only