Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-67199
Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a…
No fix yet
MEDIUM 6.9
CVE-2026-18401
The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default…
No fix yet
HIGH 7.5
CVE-2026-69152
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() doe…
Brace Expansion
1.1.18 / 2.1.4+
HIGH 8.7
CVE-2026-69079
CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a …
No fix yet
MEDIUM 5.3
CVE-2026-13586
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java…
No fix yet
MEDIUM 5.3
CVE-2026-58063
In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for …
No fix yet
MEDIUM 6.5
CVE-2026-20482
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with…
No fix yet
MEDIUM 6.9
CVE-2026-59647
In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects Bouncy Castle for Java LTS be…
No fix yet
MEDIUM 6.9
CVE-2026-59648
In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also affects Bouncy Castle for Java L…
No fix yet
MEDIUM 5.3
CVE-2026-15055
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java…
No fix yet
MEDIUM 5.9
CVE-2025-71401
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An …
No fix yet
HIGH 7.5
CVE-2026-55733
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-control…
Guardian
2.4.1+
HIGH 7.5
CVE-2026-55734
Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via…
Guardian
2.4.1+
HIGH 7.5
CVE-2026-54894
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influen…
Guardian
2.4.1+
MEDIUM 5.3
CVE-2026-67353
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields w…
No fix yet
MEDIUM 6.3
CVE-2026-67317
axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length ca…
No fix yet
HIGH 7.5
CVE-2026-67297
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body()…
No fix yet
MEDIUM 6.5
CVE-2026-55497
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed fil…
No fix yet
HIGH 7.5
CVE-2026-14539
An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows…
Mcp Toolbox For Databases
1.5.0+
HIGH 7.5
CVE-2026-12733
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
Datapower Gateway
10.5.0.22 / 10.6.0.10+
HIGH 7.5
CVE-2026-16308
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial…
No fix yet
HIGH 7.5
CVE-2026-11897
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted requ…
Websphere Application Server
26.0.0.8+
MEDIUM 5.9
CVE-2026-16971
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force attacks.
No fix yet
MEDIUM 5.9
CVE-2026-18362
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.
No fix yet
HIGH 7.5
CVE-2026-67437
OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_au…
No fix yet
HIGH 7.5
CVE-2026-67432
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo…
No fix yet
MEDIUM 5.3
CVE-2026-67430
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTranspo…
No fix yet
MEDIUM 6.2
CVE-2026-63119
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MC…
No fix yet
HIGH 7.5
CVE-2026-15975
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under …
GitLab
19.0.5 / 19.1.3+
HIGH 7.5
CVE-2026-59899
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the sup…
Netty
4.1.136 / 4.2.16+