Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.1
CVE-2026-39959
Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to malicious D-Bus peers. A peer …
Mitigation only
HIGH 7.5
CVE-2026-5440
A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directl…
Orthanc
1.12.11+
HIGH 7.5
CVE-2026-5438
A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits …
Orthanc
1.12.11+
HIGH 7.5
CVE-2026-5439
A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and tru…
Orthanc
1.12.11+
MEDIUM 6.5
CVE-2026-24661
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker…
Mattermost
2.3.2.0+
MEDIUM 6.5
CVE-2026-21388
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker…
Mattermost Server
after 2.3.1
HIGH 7.5
CVE-2026-40036
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of s…
Unfurl
2026.04+
MEDIUM 6.5
CVE-2026-39414
MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-37Z, MinIO's S3 Select featur…
Minio
after 2025-10-15t17-29-55z
HIGH 7.5
CVE-2026-23869
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turb…
Mitigation only
HIGH 7.5
CVE-2026-35401
Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations…
Saleor
3.20.118 / 3.21.54+
HIGH 7.5
CVE-2026-33756
Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multipl…
Saleor
3.20.118 / 3.21.54+
HIGH 7.5
CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in Verify…
Go
1.25.9 / 1.26.2+
HIGH 7.5
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontro…
Go
1.25.9 / 1.26.2+
MEDIUM 5.5
CVE-2026-32288
tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded …
Go
1.25.9 / 1.26.2+
CRITICAL 9.1
CVE-2026-34045
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Des…
Podman Desktop
1.26.2+
HIGH 7.5
CVE-2026-29181
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-va…
Opentelemetry
1.41.0+
MEDIUM 5.3
CVE-2026-5762
Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Extension allows HTTP DoS.
This…
Mitigation only
HIGH 7.5
CVE-2026-35526
Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphq…
Strawberry Graphql
0.312.3+
MEDIUM 6.2
CVE-2026-35480
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C…
Go Ipld Prime
0.22.0+
HIGH 7.5
CVE-2026-35405
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on ho…
Libp2p
0.17.1+
HIGH 8.2
CVE-2026-35457
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination coo…
Libp2p
0.17.1+
HIGH 7.5
CVE-2026-33034
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
ASGI requests with a missing or understated `Content-Length` h…
Django
4.2.30 / 5.2.13+
MEDIUM 6.5
CVE-2026-20431
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base s…
Mt6813 Firmware
Mitigation only
MEDIUM 6.5
CVE-2026-35441
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql…
Directus
11.17.0+
MEDIUM 6.5
CVE-2026-34755
vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/…
Vllm
0.19.0+
MEDIUM 6.5
CVE-2026-34756
vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in th…
Vllm
0.19.0+
HIGH 7.5
CVE-2026-34148
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify fo…
Fedify\/fedify
1.9.6 / 1.10.5+
HIGH 7.5
CVE-2026-34824
Mesop is a Python-based UI framework that allows users to build web applications. From version 1.2.3 to before version 1.2.5, an uncontrolled resourc…
Mesop
1.2.5+
MEDIUM 5.9
CVE-2026-34052
LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores OAuth nonces in a class-leve…
Lti Jupyterhub Authenticator
1.6.3+
HIGH 7.5
CVE-2026-35562
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a de…
Athena Odbc
2.1.0.0+