Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

759
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 121 - 140 of 155 CVEs
CVE-2026-27014 MEDIUM - 5.5

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested directories cause unbounded recursion (stack overflow) in the ROMFS archive parser. Version 6.0.1630.0 patches the issue.

Vendor: M2Team
Product: NanaZip
Published: Feb 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: linkwatch: use __dev_put() in callers to prevent UAF After linkwatch_do_dev() calls __dev_put() to release the linkwatch reference, the device refcount may drop to 1. At this point, netdev_run_todo() can proceed (since linkwatch_s...

Vendor: Linux
Product: Linux
Published: Feb 14, 2026
Source: NVD
CVE-2026-21438 MEDIUM - 5.3

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an internal session map, preventing garbage collection of their resou...

Vendor: go
Product: github.com/quic-go/webtransport-go
Published: Feb 12, 2026
Source: GitHub
CVE-2026-25762 HIGH - 7.5

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vulnerability exists in the multipart file handling logic of @adonisjs/bodyparser. When processing file uploads, the multipart parser may accumulate an unbounded amount of data in memo...

Vendor: npm
Product: @adonisjs/bodyparser
Published: Feb 06, 2026
Source: GitHub

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a remotely triggerable Out-of-Memory (OOM) denial-of-service exists in Fast -DDS when processing RTPS GAP submessages under RELIABLE QoS...

Vendor: eProsima
Product: Fast-DDS
Published: Feb 03, 2026
Source: NVD

@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, th...

Vendor: npm
Product: @isaacs/brace-expansion
Published: Feb 03, 2026
Source: GitHub
CVE-2025-58348 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/confg_tspec write operation, leading to ke...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-58347 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/p2p_certif write operation, leading to ker...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-58346 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_addts write operation, leading to ker...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-58345 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write operation, leadi...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-58344 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation in a /proc/driver/unifi0/conn_log_event_burst_to_us write operation, leading to kernel...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-58343 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/create_tspec write operation, leading to k...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-58342 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/uapsd write operation, leading to kernel m...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-58341 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_cert_disable_ht_vht write operation, le...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD
CVE-2025-58340 MEDIUM - 6.2

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 2200, 1330, 1380, 1480, 1580, W920, W930, and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_delts write operation, leading to ker...

Vendor: samsung
Product: exynos_980_firmware
Published: Feb 03, 2026
Source: NVD

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a ReadableStream (or Response with a Web Stream body) via r...

Vendor: npm
Product: fastify
Published: Feb 02, 2026
Source: GitHub
CVE-2026-0599 HIGH - 7.5

A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a blocking HTTP GET req...

Vendor: pip
Product: text-generation
Published: Feb 02, 2026
Source: NVD
CVE-2026-23881 HIGH - 7.7

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of service by crafting policies that exponentially ...

Vendor: kyverno
Product: kyverno
Published: Jan 27, 2026
Source: NVD
CVE-2025-59472 MEDIUM - 5.9

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely relate...

Vendor: vercel
Product: next
Published: Jan 26, 2026
Source: NVD
CVE-2026-24401 MEDIUM - 6.5

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record, where the alias and canonical n...

Vendor: avahi
Product: avahi
Published: Jan 24, 2026
Source: NVD