Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

760
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 155 CVEs

An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released fo...

Vendor: golang.org/x/crypto
Product: golang.org/x/crypto/ssh
Published: May 22, 2026
Source: NVD

twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments

Vendor: composer
Product: twig/intl-extra
Published: May 21, 2026
Source: GitHub

An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character conversion requests.

Vendor: Netatalk
Product: Netatalk
Published: May 21, 2026
Source: NVD
CVE-2026-5950 MEDIUM - 5.3

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through ...

Vendor: isc
Product: bind
Published: May 20, 2026
Source: NVD
CVE-2026-44608 MEDIUM - 5.9

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash....

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-44390 MEDIUM - 5.3

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound ...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-42960 CRITICAL - 10.0

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such recor...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-42959 HIGH - 7.5

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for A...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-42944 HIGH - 7.5

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses�...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-42923 MEDIUM - 5.3

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the att...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-42534 MEDIUM - 5.3

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential t...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-41292 HIGH - 7.5

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data st...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to ...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-33278 CRITICAL - 9.8

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vuln...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2026-32792 MEDIUM - 5.3

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious act...

Vendor: NLnet Labs
Product: Unbound
Published: May 20, 2026
Source: NVD
CVE-2025-57798 MEDIUM - 5.5

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.6.14 and prior contain a Denial of Service (DoS) vulnerability in the title input functionality due to a lack of proper length validation. This flaw allows an attacker to cause an Out...

Vendor: laurent22
Product: joplin
Published: May 19, 2026
Source: NVD
CVE-2026-45783 HIGH - 7.5

@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes

Vendor: npm
Product: @libp2p/kad-dht
Published: May 19, 2026
Source: GitHub
CVE-2026-45680 MEDIUM - 5.9

OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU

Vendor: go
Product: go.opentelemetry.io/obi
Published: May 18, 2026
Source: GitHub
CVE-2026-45292 MEDIUM - 5.3

OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation

Vendor: maven
Product: io.opentelemetry:opentelemetry-api
Published: May 14, 2026
Source: GitHub

Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in lib/plug/conn.ex does not obey its :length parameter. There is no upper...

Vendor: erlang
Product: plug
Published: May 14, 2026
Source: NVD