Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-12570
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the …
No fix yet
HIGH 7.5
CVE-2026-52879
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a …
No fix yet
HIGH 7.5
CVE-2026-52880
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable de…
No fix yet
MEDIUM 5.3
CVE-2026-46405
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, o…
No fix yet
HIGH 7.5
CVE-2026-15972
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connecti…
No fix yet
MEDIUM 5.3
CVE-2026-19015
Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roo…
No fix yet
MEDIUM 5.3
CVE-2025-71411
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type…
No fix yet
MEDIUM 5.3
CVE-2025-71410
Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC func…
No fix yet
HIGH 8.7
CVE-2026-67585
Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abo…
No fix yet
HIGH 7.5
CVE-2026-54225
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no …
Cxf
3.6.12 / 4.1.8+
HIGH 7.5
CVE-2026-18649
A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size …
No fix yet
HIGH 7.5
CVE-2026-71321
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_islan…
No fix yet
HIGH 7.5
CVE-2026-71314
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island …
No fix yet
MEDIUM 5.9
CVE-2026-71310
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNEC…
No fix yet
MEDIUM 6.5
CVE-2026-16100
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account…
Build Of Keycloak
26.6.5+
HIGH 7.5
CVE-2026-59675
When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. B…
No fix yet
MEDIUM 6.5
CVE-2026-68075
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache …
Qpid Broker J
10.1.0+
MEDIUM 6.5
CVE-2026-68078
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…
Qpid Broker J
10.1.0+
MEDIUM 6.5
CVE-2026-67553
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache …
Qpid Proton Dotnet
1.1.0+
MEDIUM 6.5
CVE-2026-67555
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…
Qpid Proton Dotnet
1.1.0+
MEDIUM 6.5
CVE-2026-67591
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache …
Qpid Protonj2
1.2.0+
HIGH 7.5
CVE-2026-67592
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…
Qpid Protonj2
1.2.0+
MEDIUM 6.5
CVE-2026-66275
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache …
Qpid Proton J
0.35.0+
MEDIUM 6.5
CVE-2026-66277
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso…
Qpid Proton J
0.35.0+
HIGH 7.5
CVE-2026-67465
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue af…
Qpid Proton Dotnet
1.1.0+
HIGH 7.5
CVE-2026-67588
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue af…
Qpid Protonj2
1.2.0+
HIGH 7.5
CVE-2026-68060
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This iss…
Qpid Broker J
10.1.0+
HIGH 7.5
CVE-2026-68074
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue af…
Qpid Broker J
10.1.0+
HIGH 7.5
CVE-2026-66257
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue af…
Qpid Proton J
0.35.0+
HIGH 8.7
CVE-2026-68494
The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parse…
No fix yet