Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-35406
Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection r…
Aardvark Dns
1.17.1+
MEDIUM 5.5
CVE-2026-23472
In the Linux kernel, the following vulnerability has been resolved:
serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN
uart_write_room…
Linux Kernel
6.18.20 / 6.19.10+
HIGH 7.5
CVE-2026-23451
In the Linux kernel, the following vulnerability has been resolved:
bonding: prevent potential infinite loop in bond_header_parse()
bond_header_par…
Linux Kernel
Patch available
MEDIUM 5.5
CVE-2026-23409
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix differential encoding verification
Differential encoding allows l…
Linux Kernel
5.10.253 / 5.15.203+
HIGH 7.5
CVE-2026-33891
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (D…
Forge
after 1.3.3
HIGH 7.5
CVE-2026-33699
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attacker can craft a PDF which lead…
Pypdf
6.9.2+
HIGH 7.5
CVE-2026-32287
Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU usage. This can be triggered b…
Xpath
1.3.6+
MEDIUM 5.5
CVE-2026-23298
In the Linux kernel, the following vulnerability has been resolved:
can: ucan: Fix infinite loop from zero-length messages
If a broken ucan device …
Linux Kernel
5.10.253 / 5.15.203+
HIGH 7.5
CVE-2026-4598
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.mod…
Jsrsasign
11.1.1+
HIGH 7.5
CVE-2026-33013
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applications. Versions prior to both …
Micronaut
3.10.5 / 4.10.16+
MEDIUM 6.5
CVE-2026-32889
tinytag is a Python library for reading audio file metadata. Version 2.2.0 allows an attacker who can supply MP3 files for parsing to trigger a non-t…
Tinytag
Patch available
HIGH 7.5
CVE-2026-32873
ewe is a Gleam web server. Versions 0.8.0 through 3.0.4 contain a bug in the handle_trailers function where rejected trailer headers (forbidden or un…
Ewe
3.0.5+
HIGH 7.5
CVE-2026-32875
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11.0 are vulnerable to buffer o…
Ultrajson
5.12.0+
MEDIUM 5.5
CVE-2025-71265
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: fix infinite loop in attr_load_runs_range on inconsistent metadata
W…
Linux Kernel
5.15.202 / 6.1.165+
MEDIUM 5.5
CVE-2025-71266
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: check return value of indx_find to avoid infinite loop
We found an i…
Linux Kernel
5.15.202 / 6.1.165+
MEDIUM 5.5
CVE-2025-71267
In the Linux kernel, the following vulnerability has been resolved:
fs: ntfs3: fix infinite loop triggered by zero-sized ATTR_LIST
We found an infi…
Linux Kernel
5.15.202 / 6.1.165+
HIGH 7.5
CVE-2026-32256
music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF parser (`parseExtensionObject()` …
Music Metadata
11.12.3+
HIGH 7.5
CVE-2026-30922
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncont…
Pyasn1
0.6.3+
MEDIUM 6.1
CVE-2026-4179
Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop.
Zephyr
after 4.3.0
MEDIUM 5.5
CVE-2026-32777
libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
Libexpat
2.7.5+
HIGH 7.5
CVE-2026-4111
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path.…
Patch available
MEDIUM 5.3
CVE-2026-31808
file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in the ASF (WMV/WMA) file type …
File Type
21.3.1+
MEDIUM 6.2
CVE-2025-69648
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists dat…
Binutils
after 2.45.1
MEDIUM 6.2
CVE-2025-69647
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A lo…
Binutils
after 2.45.1
HIGH 7.5
CVE-2026-2219
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream whe…
Dpkg
1.21.23 / 1.22.22+
MEDIUM 5.8
CVE-2026-20054
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the …
Mitigation only
HIGH 7.5
CVE-2026-27628
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can craft a PDF which leads to an in…
Pypdf
6.7.2+
HIGH 7.5
CVE-2026-26283
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a `continue`…
Imagemagick
6.9.13-40 / 7.1.2-15+
HIGH 7.5
CVE-2026-26066
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted pr…
Imagemagick
6.9.13-40 / 7.1.2-15+
MEDIUM 5.5
CVE-2026-27024
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.1, an attacker who uses this vulnerability can craft a PDF which leads to an in…
Pypdf
6.7.1+