Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-25043
Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibase’s password reset functional…
Budibase
3.23.25+
MEDIUM 5.5
CVE-2026-23468
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Limit BO list entry count to prevent resource exhaustion
Userspace …
Linux Kernel
6.6.140 / 6.12.86+
HIGH 7.5
CVE-2026-34827
Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mi…
Rack
3.1.21 / 3.2.6+
HIGH 7.5
CVE-2026-34593
Ash Framework is a declarative, extensible framework for building Elixir applications. Prior to version 3.22.0, Ash.Type.Module.cast_input/2 uncondit…
Ash Framework
3.22.0+
HIGH 7.5
CVE-2026-34829
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only wraps the request body in a Bo…
Rack
2.2.23 / 3.1.21+
HIGH 7.5
CVE-2026-34826
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses the HTTP Range header wi…
Rack
2.2.23 / 3.1.21+
HIGH 7.5
CVE-2026-31935
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation frames can lead to memory exh…
Suricata
7.0.15 / 8.0.4+
HIGH 7.5
CVE-2026-32145
Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing.
Th…
Wisp
2.2.2+
MEDIUM 6.5
CVE-2026-5316
A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation…
Stb Vorbis.c
after 1.22
MEDIUM 6.5
CVE-2025-66487
IBM Aspera Shares 1.9.9 through 1.11.0 does not properly rate limit the frequency that an authenticated user can send emails, which could result in e…
Aspera Shares
1.11.1+
HIGH 7.5
CVE-2026-34513
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in exces…
Aiohttp
3.13.4+
HIGH 7.5
CVE-2026-34516
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with an excessive number of multi…
Aiohttp
3.13.4+
MEDIUM 5.3
CVE-2026-34517
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multipart form fields, aiohttp read…
Aiohttp
3.13.4+
HIGH 7.5
CVE-2026-22815
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer …
Aiohttp
3.13.4+
MEDIUM 5.0
CVE-2026-34165
go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vulnerability has been identifi…
Go Git
5.17.1+
HIGH 7.5
CVE-2026-21710EPSS 26%
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application…
Node.js
after 25.8.1
HIGH 7.5
CVE-2026-32980
OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-secret-token header, allowing un…
Openclaw
2026.3.13+
HIGH 7.5
CVE-2026-33871
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger …
Netty
4.1.132 / 4.2.10+
HIGH 7.5
CVE-2026-26061
Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoints that read request bodies wi…
Fleet
4.81.0+
HIGH 7.5
CVE-2026-27880
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.
Grafana
12.1.0 / 12.2.0+
HIGH 7.5
CVE-2026-27858
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory.
Attacker can for…
Dovecot
2.3.22.1 / 2.4.3+
HIGH 7.5
CVE-2026-27857
Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands will result in client disconnec…
Dovecot
2.3.22.1 / 2.4.3+
MEDIUM 6.5
CVE-2026-33743
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user wi…
Incus
6.23.0+
MEDIUM 6.5
CVE-2026-33658
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1
Active Storage's p…
Rails
7.2.3.1 / 8.0.4.1+
MEDIUM 6.5
CVE-2026-33621
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` through `v0.8.4` contain incomplete…
Pinchtab
0.8.5+
MEDIUM 6.5
CVE-2026-33541
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparenc…
Tsportal
34+
MEDIUM 6.5
CVE-2026-33438
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions starting in 2.1.5 and prior to …
Stirling Pdf
2.5.2+
MEDIUM 5.5
CVE-2026-4897
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set…
Openshift Container Platform
Mitigation only
MEDIUM 6.5
CVE-2026-27663
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base (All versions < V26.10). The …
Mitigation only
MEDIUM 5.3
CVE-2026-33219
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious cli…
Nats Server
2.11.15 / 2.12.6+