Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-66560
Quarkus is a Cloud Native, (Linux) Container First framework for writing Java applications. Prior to versions 3.31.0, 3.27.2, and 3.20.5, a vulnerabi…
Quarkus
3.20.5 / 3.27.2+
MEDIUM 6.5
CVE-2025-66838
In Aris v10.0.23.0.3587512 and before, the file upload functionality does not enforce any rate limiting or throttling, allowing users to upload files…
Aris
after 10.0.23.0.3587512
MEDIUM 5.3
CVE-2025-15474
AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth L…
Mitigation only
HIGH 7.5
CVE-2020-36907
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unus…
No fix yet
HIGH 7.5
CVE-2025-69228
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way…
Aiohttp
3.13.3+
MEDIUM 5.3
CVE-2025-69229
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result…
Aiohttp
3.13.3+
HIGH 7.5
CVE-2025-69223
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a Do…
Aiohttp
3.13.3+
CRITICAL 9.1
CVE-2025-68456
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trig…
Craft Cms
4.16.17 / 5.8.21+
MEDIUM 6.5
CVE-2025-47208
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating system versions. If a remote…
Quts Hero
Mitigation only
HIGH 7.5
CVE-2025-68272
Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 all…
Signal K Server
2.19.0+
HIGH 7.5
CVE-2022-50799
Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server respon…
No fix yet
HIGH 7.5
CVE-2022-50695
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary h…
Impact Firmware
No fix yet
HIGH 7.5
CVE-2025-68148
FreshRSS is a free, self-hostable RSS aggregator. From version 1.27.0 to before 1.28.0, An attacker could globally deny access to feeds via proxy mod…
Freshrss
1.28.0+
HIGH 7.5
CVE-2025-11419
A flaw was found in Keycloak. This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by repeatedly initiatin…
Mitigation only
HIGH 7.5
CVE-2021-47713
Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries …
Graphql Engine
No fix yet
MEDIUM 6.5
CVE-2025-14299
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated atta…
Tapo C200 Firmware
Mitigation only
MEDIUM 6.5
CVE-2025-68389
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can allow a low-privileged authenticated user to cause Excessive Allocation …
Kibana
8.19.9 / 9.1.9+
MEDIUM 6.5
CVE-2025-68384
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allo…
Elasticsearch
8.19.9 / 9.1.9+
MEDIUM 5.3
CVE-2025-68388
Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of…
Packetbeat
8.19.9 / 9.1.9+
MEDIUM 5.3
CVE-2025-14466
A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with networ…
Mitigation only
HIGH 7.5
CVE-2025-68156
Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in Expr, including `flatten`, `mi…
Expr
1.17.7+
MEDIUM 5.3
CVE-2025-64702
quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HT…
Quic Go
0.57.0+
MEDIUM 6.5
CVE-2025-4097
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could…
GitLab
18.4.6 / 18.5.4+
HIGH 7.5
CVE-2025-12562
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could…
GitLab
18.4.6 / 18.5.4+
MEDIUM 6.5
CVE-2025-14157
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could h…
GitLab
18.4.6 / 18.5.4+
HIGH 7.5
CVE-2025-66473
XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST…
Xwiki
16.10.11 / 17.4.4+
HIGH 8.7
CVE-2025-9368
A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cyc…
No fix yet
MEDIUM 6.5
CVE-2025-41694
A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more …
Fl Switch 2708 Pn Firmware
3.50+
MEDIUM 6.5
CVE-2025-36140
IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods due to improper allocation o…
Watsonx.data
2.2.2+
MEDIUM 5.5
CVE-2025-48569
In multiple locations, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no…
Android
No fix yet