Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2025-11375
Consul and Consul Enterprise’s (“Consul”) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length …
Consul
1.18.12 / 1.20.8+
HIGH 7.5
CVE-2025-59459
An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.
Tloc100 100 Firmware
7.1.1+
HIGH 7.5
CVE-2025-11447
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could …
GitLab
18.3.5 / 18.4.3+
MEDIUM 6.5
CVE-2025-11974
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.7 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could …
GitLab
18.3.5 / 18.4.3+
HIGH 7.5
CVE-2025-10497
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could…
GitLab
18.3.5 / 18.4.3+
HIGH 7.5
CVE-2025-12044
Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regre…
Vault
1.16.27 / 1.20.5+
MEDIUM 6.5
CVE-2025-62706
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFL…
Authlib
1.6.5+
HIGH 7.5
CVE-2025-56223
A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uplo…
Signinghub
after 8.6.8
MEDIUM 5.3
CVE-2025-62672
rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs i…
Mitigation only
MEDIUM 6.9
CVE-2025-62666
Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch Extension allows HTTP DoS.Thi…
Mitigation only
CRITICAL 9.8
CVE-2025-11832
Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Floodin…
Blu Ic2 Firmware
1.20+
HIGH 7.5
CVE-2025-59778
When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause multiple containers to termi…
F5os C
1.8.2+
MEDIUM 5.3
CVE-2025-58474
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured w…
Big Ip Advanced Web Application Firewall
17.1.2+
MEDIUM 6.5
CVE-2025-55670
On BIG-IP Next CNF, BIG-IP Next SPK, and BIG-IP Next for Kubernetes systems, repeated undisclosed API calls can cause the Traffic Management Microker…
Big Ip Next Cloud Native Network Functions
after 1.9.2
HIGH 7.5
CVE-2025-41430
When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
Note: Software versi…
Big Ip Ssl Orchestrator
16.1.4 / 17.1.3+
HIGH 7.5
CVE-2025-46706
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource u…
Big Ip Next Cloud Native Network Functions
16.1.6 / 17.1.2.2+
MEDIUM 5.5
CVE-2025-55079
In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't…
Threadx
6.4.3+
HIGH 7.7
CVE-2025-9177
A denial-of-service security issue exists in the affected product and version. The security issue stems from a high number of requests sent to the we…
Mitigation only
MEDIUM 5.3
CVE-2025-41704
An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the…
Mitigation only
MEDIUM 6.9
CVE-2025-61775
Vickey is a Misskey-based microblogging platform. A vulnerability exists in Vickey prior to version 2025.10.0 where unexpired email confirmation link…
Mitigation only
HIGH 7.5
CVE-2025-61920
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JW…
Authlib
1.6.5+
MEDIUM 6.5
CVE-2025-2934
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 5.2 prior to 18.2.8, 18.3 prior to 18.3.4, and 18.4 prior to 18.4.2 that c…
GitLab
18.2.8 / 18.3.4+
HIGH 7.5
CVE-2025-10004
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the Gi…
GitLab
18.2.8 / 18.3.4+
HIGH 7.5
CVE-2025-11362
Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via…
Pdfmake
Patch available
HIGH 7.5
CVE-2025-58582
If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possi…
Enterprise Analytics
Mitigation only
MEDIUM 5.5
CVE-2025-11274
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/cod…
Assimp
No fix yet
MEDIUM 6.5
CVE-2025-52867
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can the…
Qsync Central
5.0.0.2+
MEDIUM 6.5
CVE-2025-44012
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…
Qsync Central
5.0.0.2+
MEDIUM 6.5
CVE-2025-33040
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…
Qsync Central
5.0.0.1+
MEDIUM 6.5
CVE-2025-44006
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac…
Qsync Central
5.0.0.1+