Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2025-3922
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that co…
GitLab
18.9.6 / 18.10.4+
MEDIUM 6.5
CVE-2025-6016
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that cou…
GitLab
18.9.6 / 18.10.4+
MEDIUM 6.5
CVE-2026-1660
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that un…
GitLab
18.9.6 / 18.10.4+
MEDIUM 6.5
CVE-2025-0186
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that co…
GitLab
18.9.6 / 18.10.4+
HIGH 7.5
CVE-2026-33254
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial o…
Dnsdist
1.9.13 / 2.0.4+
HIGH 7.5
CVE-2026-33594
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accu…
Dnsdist
1.9.13 / 2.0.4+
HIGH 7.5
CVE-2026-33595
A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources wer…
Dnsdist
1.9.13 / 2.0.4+
HIGH 7.5
CVE-2026-33256
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…
Recursor
5.2.9 / 5.3.6+
HIGH 7.5
CVE-2026-33257
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…
Authoritative
1.9.13 / 2.0.4+
HIGH 7.5
CVE-2026-33258
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.
Recursor
5.2.9 / 5.3.6+
HIGH 7.5
CVE-2026-33260
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…
Authoritative
1.9.13 / 2.0.4+
HIGH 7.5
CVE-2026-40881
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 mess…
Zebra Network
4.3.1 / 5.0.1+
MEDIUM 6.1
CVE-2026-33812
Parsing a malicious font file can cause excessive memory allocation.
Image
0.39.0+
MEDIUM 5.5
CVE-2026-40608
Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contai…
Next Ai Draw.io
0.4.15+
CRITICAL 9.8
CVE-2026-40498
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can access diagnostic and system …
Freescout
1.8.213+
MEDIUM 6.5
CVE-2026-39396
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downlo…
Openbao
2.5.3+
HIGH 7.5
CVE-2026-5807
Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rek…
Vault
2.0.0+
HIGH 8.7
CVE-2026-39313
mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in the H…
Patch available
MEDIUM 6.5
CVE-2026-35469
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate att…
Mitigation only
HIGH 7.5
CVE-2026-40192
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, …
Pillow
12.2.0+
HIGH 7.5
CVE-2026-3505
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcp…
Patch available
HIGH 8.2
CVE-2026-40104
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc…
Xwiki
16.10.16 / 17.4.8+
CRITICAL 9.8
CVE-2026-31283
In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address. which can be used for an Ema…
Mitigation only
HIGH 7.5
CVE-2026-40395
Varnish Enterprise before 6.0.16r12 allows a "workspace overflow" denial of service (daemon panic) for shared VCL. The headerplus.write_req0() functi…
Varnish Enterprise
after 6.0.15
HIGH 7.5
CVE-2026-40073
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under certain circumstances, reque…
Kit
2.57.1+
HIGH 7.1
CVE-2026-35602
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses the attacker-controlled Size fi…
Vikunja
2.3.0+
HIGH 7.5
CVE-2026-39304
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do…
Activemq
5.19.4 / 6.2.4+
HIGH 7.5
CVE-2026-40115
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire HTTP request body into …
Praisonai
4.5.128+
HIGH 7.5
CVE-2026-40116
PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from a…
Praisonai
4.5.128+
MEDIUM 5.3
CVE-2026-35633
OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger …
Openclaw
2026.3.22+