Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

757
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 141 - 155 of 155 CVEs
CVE-2025-67125 MEDIUM - 4.4

A signed integer overflow in docopt.cpp v0.6.2 (LeafPattern::match in docopt_private.h) when merging occurrence counters (e.g., default LONG_MAX + first user "-v/--verbose") can cause counter wrap (negative/unbounded semantics) and lead to logic/policy bypass in applications that rely on o...

Vendor: n/a
Product: n/a
Published: Jan 23, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: usb: phy: isp1301: fix non-OF device reference imbalance A recent change fixing a device reference leak in a UDC driver introduced a potential use-after-free in the non-OF case as the isp1301_get_client() helper only increases the...

Vendor: Linux
Product: Linux
Published: Jan 23, 2026
Source: NVD
CVE-2025-56353 HIGH - 7.5

In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), a memory leak occurs due to the broker's failure to validate or reject malformed UTF-8 strings in topic filters. An attacker can exploit this by sending repeated subscription requests with arbitrarily large or invalid fil...

Vendor: n/a
Product: n/a
Published: Jan 20, 2026
Source: NVD
CVE-2025-14435 MEDIUM - 6.5

Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.

Vendor: mattermost
Product: mattermost_server
Published: Jan 16, 2026
Source: NVD
CVE-2026-22036 HIGH - 7.5

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerabilit...

Vendor: nodejs
Product: undici
Published: Jan 14, 2026
Source: NVD

TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted output implementation used within the ZigBee / IEEE 802.15.4 networking stack. The implementation formats output into a fixed-size global buffer and concatenates strings for %s format...

Published: Jan 14, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer When advancing the target expiration for the guest's APIC timer in periodic mode, set the expiration to "now" if the target expiration i...

Published: Jan 14, 2026
Source: NVD
CVE-2026-22213 CRITICAL - 9.8

RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the tapslip6 utility. The vulnerability is caused by unsafe string concatenation in the devopen() function, which constructs a device path using unbounded user-controlled input. The utility ...

Vendor: riot-os
Product: riot
Published: Jan 12, 2026
Source: NVD
CVE-2024-58339 HIGH - 7.5

LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query() logic generates SQL statements from a user-supplied prompt and executes them via vn.run_sql() without...

Vendor: llamaindex
Product: llamaindex
Published: Jan 12, 2026
Source: NVD
CVE-2026-22026 HIGH - 7.5

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the libcurl write_callback function in the KM...

Vendor: nasa
Product: cryptolib
Published: Jan 10, 2026
Source: NVD
CVE-2026-22189 CRITICAL - 9.8

Panda3D versions up to and including 1.10.16 egg-mkfont contains a stack-based buffer overflow vulnerability due to use of an unbounded sprintf() call with attacker-controlled input. When constructing glyph filenames, egg-mkfont formats a user-supplied glyph pattern (-gp) into a fixed-size stack buf...

Vendor: cmu
Product: panda3d
Published: Jan 07, 2026
Source: NVD
CVE-2026-22188 MEDIUM - 5.5

Panda3D versions up to and including 1.10.16 deploy-stub contains a denial of service vulnerability due to unbounded stack allocation. The deploy-stub executable allocates argv_copy and argv_copy2 using alloca() based directly on the attacker-controlled argc value without validation. Supplying a lar...

Vendor: cmu
Product: panda3d
Published: Jan 07, 2026
Source: NVD
CVE-2025-67419 HIGH - 7.5

A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles dur...

Vendor: evershop
Product: evershop
Published: Jan 05, 2026
Source: NVD
CVE-2026-21452 HIGH - 7.5

MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior to 0.9.11 when deserializing .msgpack files containing EXT32 objects with attacker-controlled payload lengths. While MessagePack-Java parses extension headers lazily, it later tru...

Published: Jan 02, 2026
Source: NVD
CVE-2025-68272 HIGH - 7.5

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access request endpoint (`/signalk/v1/access/requests`). This causes a &quo...

Vendor: signalk
Product: signal_k_server
Published: Jan 01, 2026
Source: NVD