Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.2
CVE-2025-43211
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.…
Safari
2.6 / 11.6+
MEDIUM 6.5
CVE-2025-5253
Allocation of Resources Without Limits or Throttling vulnerability in Kron Technologies Kron PAM allows HTTP DoS.
This issue affects Kron PAM: befor…
Mitigation only
HIGH 7.5
CVE-2025-53538
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions 7.…
Suricata
7.0.11+
MEDIUM 5.3
CVE-2025-54121
Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In ver…
Patch available
HIGH 7.5
CVE-2025-44652
In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when…
Rax30 Firmware
Mitigation only
HIGH 8.8
CVE-2025-53628
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique lin…
Cpp Httplib
0.20.1+
HIGH 7.5
CVE-2025-53629
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked…
Cpp Httplib
0.23.0+
HIGH 7.5
CVE-2025-53634
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout s…
Chall Manager
0.1.4+
HIGH 7.5
CVE-2025-53530
WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific…
Wegia
3.3.0+
HIGH 7.5
CVE-2025-53531
WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific…
Wegia
3.3.0+
HIGH 7.5
CVE-2025-48367
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to cl…
Redis
6.2.19 / 7.2.10+
HIGH 8.8
CVE-2025-7070
A vulnerability has been found in IROAD Dashcam Q9 up to 20250624 and classified as problematic. Affected by this vulnerability is an unknown functio…
Q9 Firmware
after 2025-06-24
MEDIUM 6.5
CVE-2025-3279
An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could h…
GitLab
17.11.5 / 18.0.3+
HIGH 7.5
CVE-2025-2403
A denial-of-service vulnerability due to improper prioritization of network traffic over protection mechanism exists in Relion 670/650 and SAM600-IO …
Mitigation only
HIGH 8.8
CVE-2025-52568
NeKernal is a free and open-source operating system stack. Prior to version 0.0.3, there are several memory safety issues that can lead to memory cor…
Patch available
MEDIUM 6.5
CVE-2025-48467
Successful exploitation of the vulnerability could allow an attacker to cause repeated reboots, potentially leading to remote denial-of-service and s…
Wise 4010lan Firmware
No fix yet
HIGH 7.5
CVE-2025-3221
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service due to insufficient validation…
Infosphere Information Server
after 11.7.1.6
MEDIUM 5.3
CVE-2025-4820
Impact
Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t…
Quiche
0.24.4+
HIGH 7.5
CVE-2025-4821
Impact
Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster t…
Quiche
0.24.4+
HIGH 7.5
CVE-2025-48976EPSS 68%
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
This issue affects …
Commons Fileupload
1.6+
HIGH 7.5
CVE-2025-48988EPSS 57%
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7…
Tomcat
9.0.106 / 10.1.42+
MEDIUM 6.5
CVE-2025-5996
An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack o…
GitLab
17.10.8 / 17.11.4+
HIGH 7.5
CVE-2025-1516
An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper i…
GitLab
17.10.8 / 17.11.4+
HIGH 7.5
CVE-2025-1478
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of…
GitLab
17.10.7 / 17.11.3+
HIGH 7.5
CVE-2025-25032
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a …
Cognos Analytics
after 12.0.4
MEDIUM 6.5
CVE-2025-48448
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin A…
Admin Audit Trail
1.0.5+
MEDIUM 6.6
CVE-2025-4605
A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may…
Maya
2025.3.1+
HIGH 7.5
CVE-2025-49140
Pion Interceptor is a framework for building RTP/RTCP communication software. Versions v0.1.36 through v0.1.38 contain a bug in a RTP packet factory …
Patch available
HIGH 7.5
CVE-2025-48053
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version…
Discourse
3.4.4 / 3.5.0+
MEDIUM 5.7
CVE-2025-25207
The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with deve…
Mitigation only