<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Denial of Service (DoS) (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/dos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/dos-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Denial of Service (DoS) (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-37462 – An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37462</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37462</strong></p>
  <p>An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9516 – Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9516</guid>
    <pubDate>Wed, 03 Jun 2026 01:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9516</strong></p>
  <p>Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws.  To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When decoding aborts through a Perl exception, for example a filter_json_object callback…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-14036 – Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-14036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-14036</guid>
    <pubDate>Tue, 02 Jun 2026 22:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-14036</strong></p>
  <p>Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by sending specially crafted, unencrypted SDC messages during the discovery process. Attackers with access to the hospital network can send malformed SDC packets to exhaust CPU resources in the affected process, causing further SDC mes…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-14036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8035 – Improper input validation in the NI-PAL kernel driver may allow a local authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8035</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8035</strong></p>
  <p>Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due to a NULL pointer dereference. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48597 – Allocation of Resources Without Limits or Throttling vulnerability in elixir-tes...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48597</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48597</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint.  Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing request to a BEAM atom via String.to_atom(uri.scheme) with no allow-list validation. BEAM atoms are never garbage-collected and the atom table is bounded (approxi…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48594 – Improper Handling of Highly Compressed Data (Data Amplification) vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48594</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48594</strong></p>
  <p>Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies.  When Tesla.Middleware.DecompressResponse or Tesla.Middleware.Compression is included in a Tesla middleware pipeline, HTTP response bodies are decompressed eagerly with no size limit. The decompress_body/2 function in lib/t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1871 – TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1871</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1871</strong></p>
  <p>TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request.  Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition.  This…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45686 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45686</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45686</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as set, add, replace, append, prepend, or cas, OBI accepts extremely large…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45685 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45685</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45685</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service. The parser operates on raw attacker-controlled network payloads…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70099 – A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70099</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70099</strong></p>
  <p>A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesystem image with malformed directory entries. During directory iteration, the code may fail to validate the directory entry pointer before accessing the name_len field, resulting in a segmentation fault.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43958 – A flaw was found in rrdcached, a component of rrdtool. A local attacker with acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43958</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43958</strong></p>
  <p>A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10118 – A flaw was found in Poppler's Splash backend. A remote attacker could exploit th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10118</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10118</strong></p>
  <p>A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49361 – Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49361</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49361</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49361</strong></p>
  <p>Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap memory on TabletServer and CoordinatorServer by sending specially crafted frame headers, resulting in denial of service.  This issue affects Apache Fluss (incubating): 0.8.0 and 0.9.0.  Users are rec…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49361">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25426 – WinMTR 0.91 contains a denial of service vulnerability that allows attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25426</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25426</strong></p>
  <p>WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated characters. Attackers can create a specially crafted input file with 238 bytes of data to trigger a buffer overflow condition that causes the application to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46527 – cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46527</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46527</strong></p>
  <p>cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an attacker can send an HTTP request that includes an X-Forwarded-For header whose value parses to no valid IP segments. The code path then executes get_client_ip(), which calls front() on an empty std::vec…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44420 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44420</guid>
    <pubDate>Fri, 29 May 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44420</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process (remote DoS) and may be exploitable for code execution because it corrupts heap memory. This vulne…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45615 – mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45615</guid>
    <pubDate>Fri, 29 May 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45615</strong></p>
  <p>mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload for a variable-length, non-negative INTEGER type, the decoder fails to validate the required bytes before extracting the Most Significant Bit (MSB). Th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9509 – An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9509</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9509</guid>
    <pubDate>Fri, 29 May 2026 13:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9509</strong></p>
  <p>An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST requests to the ‘/api/migration’ endpoint. This request triggers a failure that halts critical processes, leaving the system offline until the services or server are manually restarted. As a result, access…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9509">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39929 – Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39929</guid>
    <pubDate>Thu, 28 May 2026 22:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39929</strong></p>
  <p>Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46835 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46835</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46835</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46834 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46834</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46834</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46829 – Vulnerability in Oracle REST Data Services (component: Mongoapi).  Supported ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46829</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46829</guid>
    <pubDate>Thu, 28 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46829</strong></p>
  <p>Vulnerability in Oracle REST Data Services (component: Mongoapi).  Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) o…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46829">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35266 – Vulnerability in Oracle REST Data Services (component: Core).  Supported version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35266</guid>
    <pubDate>Thu, 28 May 2026 21:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35266</strong></p>
  <p>Vulnerability in Oracle REST Data Services (component: Core).  Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle REST Data Services.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle REST Data Services…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45044 – RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45044</guid>
    <pubDate>Thu, 28 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45044</strong></p>
  <p>RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any unauthenticated HTTP client to invoke profiling handlers without credentials. On supported builds (e.g., glibc), the handler invokes a fixed 60-second CPU profiling operation (dump_cpu_pprof_for(Dura…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44521 – elFinder is an open-source file manager for web, written in JavaScript using jQu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44521</guid>
    <pubDate>Wed, 27 May 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44521</strong></p>
  <p>elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through a crafted target file hash. Successful exploitation can lead to unauthorized dat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44378 – Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44378</guid>
    <pubDate>Wed, 27 May 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44378</strong></p>
  <p>Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such BER encodings were accepted even in structures which are required to be encoded as DER, which prohibits indefinite length encodings. This vulnerability is fixed in 3.12.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44328 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44328</guid>
    <pubDate>Wed, 27 May 2026 17:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44328</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without inbound OAuth2 middleware. On top of that, the DELETE /upi/v1/upNodesLinks/{upNodeRef} handler unconditionally dereferences upNode.UPF after the type-guarded async release, even though AN-typed nodes are constructed without a UPF object. As a result, a singl…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8180 – IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8180</guid>
    <pubDate>Wed, 27 May 2026 14:17:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8180</strong></p>
  <p>IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd service to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8175 – IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8175</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8175</strong></p>
  <p>IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7528 – IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to unco...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7528</guid>
    <pubDate>Wed, 27 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7528</strong></p>
  <p>IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1718 – IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1718</guid>
    <pubDate>Wed, 27 May 2026 14:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1718</strong></p>
  <p>IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49017 – In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49017</guid>
    <pubDate>Wed, 27 May 2026 02:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49017</strong></p>
  <p>In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exha…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44966 – Velocity.js is a JavaScript implementation of the Apache Velocity template engin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44966</guid>
    <pubDate>Tue, 26 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44966</strong></p>
  <p>Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to Denial of Servic…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8856 – IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8856</guid>
    <pubDate>Tue, 26 May 2026 18:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8856</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8855 – IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8855</guid>
    <pubDate>Tue, 26 May 2026 18:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8855</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8854 – IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8854</guid>
    <pubDate>Tue, 26 May 2026 18:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8854</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-825</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8835 – IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8835</guid>
    <pubDate>Tue, 26 May 2026 18:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8835</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8834 – IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8834</guid>
    <pubDate>Tue, 26 May 2026 18:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8834</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24200 – NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24200</guid>
    <pubDate>Tue, 26 May 2026 18:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24200</strong></p>
  <p>NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24196 – NVIDIA Display Driver for Linux contains a vulnerability where a user could caus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24196</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24196</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24195 – NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24195</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24195</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24194 – NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24194</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24194</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24193 – NVIDIA Display Driver for Windows and Linux contains a vulnerability where an at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24193</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24193</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24192 – NVIDIA Display Driver for Linux contains a vulnerability where an attacker could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24192</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24192</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24191 – NVIDIA Display Driver for Windows contains a vulnerability where an attacker cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24191</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24191</strong></p>
  <p>NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24190 – NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24190</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24190</strong></p>
  <p>NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24187 – NVIDIA Display Driver for Linux contains a vulnerability where an attacker could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24187</guid>
    <pubDate>Tue, 26 May 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24187</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8850 – IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8850</guid>
    <pubDate>Tue, 26 May 2026 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8850</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48864 – A flaw was found in libsolv. This heap buffer overflow occurs during the decompr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48864</guid>
    <pubDate>Tue, 26 May 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48864</strong></p>
  <p>A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of progr…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48692 – FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 500...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48692</guid>
    <pubDate>Tue, 26 May 2026 16:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48692</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line 477) and a source code comment explicitly acknowledges 'Listen on the given address without any authentication mechanism.' None of the RPC methods in src/api.cpp (ExecuteBan, ExecuteUnBan, Get…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48132 – The Security Gateway does not correctly validate a length value in certain IKE p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48132</guid>
    <pubDate>Tue, 26 May 2026 14:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48132</strong></p>
  <p>The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48131 – The VPN service may mishandle an unexpected IKE fragment value received on the I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48131</guid>
    <pubDate>Tue, 26 May 2026 14:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48131</strong></p>
  <p>The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8047 – The affected products perform improper length checking when parsing incoming HTT...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8047</guid>
    <pubDate>Tue, 26 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8047</strong></p>
  <p>The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9496 – Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9496</guid>
    <pubDate>Tue, 26 May 2026 07:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9496</strong></p>
  <p>Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by supplying a specially crafted spec.rawSpec value that triggers the function’s regex replacement and string-manipulation logic,  causing excessive CPU consumption and potentially stalling or crashing the process.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25368 – Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25368</guid>
    <pubDate>Mon, 25 May 2026 15:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25368</strong></p>
  <p>Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44064 – An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44064</guid>
    <pubDate>Thu, 21 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44064</strong></p>
  <p>An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or cause a denial of service via a crafted ASP request.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44062 – A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44062</guid>
    <pubDate>Thu, 21 May 2026 08:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44062</strong></p>
  <p>A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character set data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44060 – An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44060</guid>
    <pubDate>Thu, 21 May 2026 08:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44060</strong></p>
  <p>An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44050 – A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44050</guid>
    <pubDate>Thu, 21 May 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44050</strong></p>
  <p>A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44049 – An out-of-bounds write due to improper null termination in convert_charset() in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44049</guid>
    <pubDate>Thu, 21 May 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44049</strong></p>
  <p>An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44048 – A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44048</guid>
    <pubDate>Thu, 21 May 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44048</strong></p>
  <p>A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44047 – An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44047</guid>
    <pubDate>Thu, 21 May 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44047</strong></p>
  <p>An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9102 – A path traversal vulnerability exists in the Altium Enterprise Server Comparison...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9102</guid>
    <pubDate>Wed, 20 May 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9102</strong></p>
  <p>A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file upload APIs. A regular authenticated workspace user can supply a crafted filename in the multipart Content-Disposition header to escape the intended temporary upload directory and write arbitrary files to any location on the server filesystem.     Because…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24218 – NVIDIA DGX OS contains a vulnerability in the factory provisioning process, wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24218</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24218</strong></p>
  <p>NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where  the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution,…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24217 – NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24217</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24217</strong></p>
  <p>NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-29</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24216 – NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a des...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24216</guid>
    <pubDate>Wed, 20 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24216</strong></p>
  <p>NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9064 – A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9064</guid>
    <pubDate>Wed, 20 May 2026 10:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9064</strong></p>
  <p>A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap al…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42959 – NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42959</guid>
    <pubDate>Wed, 20 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42959</strong></p>
  <p>NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could increase the ANSWER section count and authority f…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-824</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41292 – NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degrada...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41292</guid>
    <pubDate>Wed, 20 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41292</strong></p>
  <p>NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. U…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33278 – NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33278</guid>
    <pubDate>Wed, 20 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33278</strong></p>
  <p>NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-que…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24214 – NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24214</guid>
    <pubDate>Wed, 20 May 2026 04:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24214</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, or denial of service.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24213 – NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24213</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24213</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24210 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24210</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24210</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24209 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24209</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24209</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24207 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24207</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24207</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24206 – NVIDIA Triton Inference Server contains a vulnerability where an attacker could ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24206</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24206</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24163 – NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24163</guid>
    <pubDate>Wed, 20 May 2026 04:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24163</strong></p>
  <p>NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could  cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33255 – NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33255</guid>
    <pubDate>Wed, 20 May 2026 04:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33255</strong></p>
  <p>NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability might lead to code execution, denial of service, data tampering, and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32882 – libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32882</guid>
    <pubDate>Tue, 19 May 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32882</strong></p>
  <p>libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) inste…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33633 – Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33633</guid>
    <pubDate>Tue, 19 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33633</strong></p>
  <p>Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42100 – Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42100</guid>
    <pubDate>Tue, 19 May 2026 14:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42100</strong></p>
  <p>Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly.   The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-228</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7307 – A flaw was found in Keycloak. A remote, unauthenticated attacker can send a spec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7307</guid>
    <pubDate>Tue, 19 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7307</strong></p>
  <p>A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes unavailable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1286</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8813 – This affects versions of the package exifreader before 4.39.0. A crafted image c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8813</guid>
    <pubDate>Tue, 19 May 2026 07:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8813</strong></p>
  <p>This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing, ExifReader repeatedly processes the same record and appends entries to an array without sufficient bounds validation, causing excessive memory growth. In applications that parse attacker-supplied ima…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25781 – in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25781</guid>
    <pubDate>Tue, 19 May 2026 04:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25781</strong></p>
  <p>in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33232 – AutoGPT is a workflow automation platform for creating, deploying, and managing ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33232</guid>
    <pubDate>Tue, 19 May 2026 02:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33232</strong></p>
  <p>AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of Service (DoS) through the server due to uncontrolled disk space consumption. The download_agent_file endpoint creates persistent temporary files for every request but fails to delete them after they…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45230 – DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45230</guid>
    <pubDate>Mon, 18 May 2026 18:17:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45230</strong></p>
  <p>DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and disabled-by-default authentication control to traverse outside the intended application…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56352 – In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the br...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56352</guid>
    <pubDate>Mon, 18 May 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56352</strong></p>
  <p>In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length Client ID while CleanSession is set to 0, the broker correctly replies with a CONNACK return code 0x02 (Identifier Rejected) but fails to explicitly close the TCP connection. Since the surrounding conn…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42009 – A flaw was found in gnutls. A remote attacker could exploit an issue in the Data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42009</guid>
    <pubDate>Mon, 18 May 2026 13:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42009</strong></p>
  <p>A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-475</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47973 – Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47973</guid>
    <pubDate>Sat, 16 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47973</strong></p>
  <p>Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47972 – Sticky Notes &amp; Color Widgets 1.4.2 contains a denial of service vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47972</guid>
    <pubDate>Sat, 16 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47972</strong></p>
  <p>Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can paste large payloads of repeated characters into note fields to trigger application crashes and make the application stop responding.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47971 – My Notes Safe 5.3 contains a denial of service vulnerability that allows attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47971</guid>
    <pubDate>Sat, 16 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47971</strong></p>
  <p>My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47970 – Macaron Notes 5.5 contains a denial of service vulnerability that allows attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47970</guid>
    <pubDate>Sat, 16 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47970</strong></p>
  <p>Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can generate a payload containing 350000 repeated characters and paste it into a note field to trigger application crash and stop functionality.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47969 – Color Notes 1.4 contains a denial of service vulnerability that allows attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47969</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47969</guid>
    <pubDate>Sat, 16 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47969</strong></p>
  <p>Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350,000 repeated characters and paste it twice into a new note to cause the application to stop responding.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47969">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8696 – radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8696</guid>
    <pubDate>Fri, 15 May 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8696</strong></p>
  <p>radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbitrary code by sending malformed thread information responses. Attackers can trigger the vulnerability by causing qsThreadInfo to fail after qfThreadInfo successfully allocates RDebugPid structures, re…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8686 – Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8686</guid>
    <pubDate>Fri, 15 May 2026 19:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8686</strong></p>
  <p>Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.    To remediate this issue, users should upgrade to v5.0.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47959 – WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47959</guid>
    <pubDate>Fri, 15 May 2026 19:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47959</strong></p>
  <p>WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads to trigger server out-of-memory conditions and MySQL connection errors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8695 – radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list()...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8695</guid>
    <pubDate>Fri, 15 May 2026 17:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8695</strong></p>
  <p>radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers to trigger memory corruption by sending a valid qfThreadInfo response followed by a malformed qsThreadInfo response. Attackers can exploit this vulnerability through GDB remote debugging to cause a denial of service or potentially achieve code execution by manipulating thread lis…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38728 – An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38728</guid>
    <pubDate>Fri, 15 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38728</strong></p>
  <p>An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29938 – An unchecked return value within the AMD Platform Management Framework (PMF) cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29938</guid>
    <pubDate>Fri, 15 May 2026 03:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29938</strong></p>
  <p>An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43907 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43907</guid>
    <pubDate>Thu, 14 May 2026 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43907</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer overflow in QueryRGBBufferSizeInternal() in DPXColorConverter.cpp leads to a heap-based out-of-bounds write when processing crafted DPX image files. The function computes buffer sizes using 32-bit signed integer arithmet…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43907">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
