By severity

High-severity vulnerabilities

CVEs rated High by CVSS, with SEC.co remediation and prioritization guidance.

4140 published vulnerabilities · page 31 of 42

  • CVE-2026-48979HIGH 7.5

    The PHP Standard Library (PSL) contains a flaw in its HTTP/2 server implementation that allows an attacker to bypass security controls by sending mismatched request sizes. Specifically, the server doesn't verify that the actual data received matches the size declared in the request headers, enabling an attacker to slip additional data past application-level checks or truncate requests early. This is similar to HTTP request smuggling attacks that have historically been used to bypass firewalls, WAFs, and other protective measures. Most developers using PSL through its documented APIs are unaffected; only those directly using the low-level ServerConnection class with untrusted client input face exposure.

  • CVE-2026-48995HIGH 7.5

    pnpm, a widely-used Node.js package manager, fails to validate the integrity of dependencies downloaded from GitHub's codeload service before installation. An attacker who compromises codeload.github.com or intercepts traffic to it could serve malicious packages that pnpm will install without verification, even if the project's lockfile specifies different content. This occurs because pnpm does not store or check cryptographic hashes of packages from this specific source, creating a supply-chain risk for any project using pnpm to fetch dependencies from GitHub.

  • CVE-2026-49049HIGH 7.5

    An unauthenticated security flaw in the Helix3 plugin for Joomla allows attackers to delete files, write JSON files, and modify template settings without needing user credentials. The vulnerability exists in an exposed AJAX handler that lacks proper access controls, making it trivial for any internet-connected attacker to exploit remotely. This poses an immediate risk to site integrity and functionality.

  • CVE-2026-49056HIGH 7.5

    A vulnerability in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows attackers to access sensitive business and customer data without needing to log in. The flaw affects all versions up to and including 4.9.4. An attacker can retrieve information such as invoice details, customer addresses, and order data by making direct requests to the plugin—no authentication or user interaction required. This poses a significant risk to e-commerce sites relying on this plugin, as customer personal information and financial records could be exposed.

  • CVE-2026-49061HIGH 7.5

    WPC Product Options for WooCommerce versions 3.2.1 and earlier contain a vulnerability that allows attackers to download arbitrary files from an affected server without authentication. An attacker can exploit this remotely by crafting requests that bypass path validation controls, potentially exposing sensitive configuration files, database backups, source code, or other confidential data stored on the web server. No user interaction or special privileges are required to attempt exploitation.

  • CVE-2026-49064HIGH 7.5

    Stiofan GetPaid contains a flaw that causes the application to inadvertently leak sensitive information in outgoing data transmissions. An unauthenticated remote attacker can retrieve this embedded sensitive data without requiring special privileges or user interaction. The vulnerability affects GetPaid versions up to and including 2.8.49.

  • CVE-2026-49110HIGH 7.5

    The Upsell Order Bump Offer plugin for WooCommerce versions 3.1.4 and earlier contains an authentication bypass vulnerability that allows attackers to perform actions without logging in. An attacker can send specially crafted requests to the application to manipulate order data or modify plugin settings, potentially leading to unauthorized changes to orders or store configuration. This vulnerability requires no user interaction and can be exploited remotely by anyone with network access to the affected WooCommerce store.

  • CVE-2026-49119HIGH 7.5

    Gradio, a popular open-source library for building machine learning interfaces, contains a flaw in its FileExplorer component that allows attackers to read files outside the intended directory without authentication. By crafting malicious file paths, an attacker can bypass the directory restrictions and access sensitive files anywhere on the system. This is a path traversal vulnerability—a classic technique for escaping sandbox boundaries.

  • CVE-2026-49128HIGH 7.5

    Music Player Daemon (MPD) versions before 0.24.11 allow unauthenticated attackers to access files and directories outside the configured music library through specially crafted commands. By exploiting how the application constructs file paths, an attacker can bypass intended boundaries and read arbitrary image files or enumerate directory contents that the MPD process has permission to access. This is a path traversal flaw that turns a music streaming service into an unintended information disclosure vector.

  • CVE-2026-49136HIGH 7.5

    Banana Slides version 0.4.0 and earlier contains a path traversal flaw that lets unauthenticated attackers read image files from anywhere on the server, not just the intended uploads folder. An attacker can craft specially formatted markdown in page descriptions to trick the application into opening files from sibling directories. The vulnerability stems from a flawed directory check that doesn't properly validate path boundaries, allowing an attacker to bypass the intended confinement and access sensitive image-format files. This affects all instances of Banana Slides up to version 0.4.0; a fix has been released in commit e8bc490.

  • CVE-2026-49145HIGH 7.5

    App::Ack, a popular code-search tool for Perl developers, has a vulnerability in how it handles configuration files. When developers clone or use a project containing a malicious .ackrc configuration file, the tool can be tricked into reading and processing arbitrary files on the system—even those outside the project directory. This happens because the security blocklist that prevents dangerous options in project-level configs is incomplete. An attacker who commits a crafted .ackrc to a repository can exploit this to extract sensitive file contents when other developers run ack.

  • CVE-2026-49146HIGH 7.5

    App::Ack, a popular Perl-based code search tool, has a vulnerability in versions before 3.10.0 that allows an attacker to crash the application by exhausting system memory. The vulnerability exists because ack automatically loads configuration options from a .ackrc file in the current project directory without properly validating the values. An attacker can set extremely large values for the context buffer options (used to display lines before or after search matches), forcing ack to allocate massive amounts of RAM until the system runs out of memory and the program terminates. This attack requires only that a user clone or work with a malicious repository—no special privileges or authentication needed.

  • CVE-2026-49147HIGH 7.5

    App::Ack, a popular command-line search utility for Perl, fails to sanitize terminal escape sequences embedded in filenames across multiple output modes. When a user or an automated process searches files with ack and a filename contains ANSI escape codes (such as color or cursor-movement sequences), those bytes pass directly to the terminal unsanitized. This can allow an attacker to manipulate terminal display, overwrite previous output, or inject malicious control sequences into downstream tools that consume ack's output. The vulnerability affects versions through 3.10.0, though a partial fix was introduced in 3.10.0 that addresses some—but not all—output paths.

  • CVE-2026-49160HIGH 7.5

    A flaw in how Windows handles HTTP/2 network traffic allows an attacker to overwhelm and crash services by sending specially crafted requests that consume excessive system resources. The attacker does not need credentials or user interaction; they can trigger the problem remotely across a network. This is a denial-of-service vulnerability affecting multiple versions of Windows 10, Windows 11, and Windows Server products.

  • CVE-2026-49187HIGH 7.5

    CVE-2026-49187 is a confidentiality vulnerability in Acer Connect M6E 5G devices where hard-coded resource files embedded in the APK firmware do not expire and can be accessed via a shared mechanism. This allows an attacker to retrieve sensitive information from the device without authentication. The vulnerability does not permit data modification or service disruption, but the information exposure risk is significant enough to warrant prompt remediation.

  • CVE-2026-49193HIGH 7.5

    CVE-2026-49193 is a high-severity vulnerability affecting Acer Connect M6E 5G devices where overly permissive cloud storage container settings allow telemetry data to be exposed publicly on the internet. An attacker does not need authentication or special access to view sensitive telemetry information—it is simply accessible to anyone who knows where to look. This is a data exposure risk that could reveal operational and usage patterns of affected devices and their networks.

  • CVE-2026-49218HIGH 7.5

    ImageMagick, a widely used image editing and manipulation tool, contains a flaw in how it processes DCM (DICOM medical imaging) files. The vulnerability allows specially crafted DCM files with invalid dimensions to pass validation checks, potentially causing the application to crash when performing subsequent operations on the image. This is a denial-of-service issue affecting the availability of systems that rely on ImageMagick for image processing.

  • CVE-2026-49233HIGH 7.5

    Routinator, a critical tool for validating BGP route origins, contains a path traversal vulnerability in how it processes rsync module names. An attacker can craft a malicious rsync URI with directory traversal sequences (like ..) in the module component, allowing unauthorized access to files outside the intended cache directory. This could expose the entire rsync cache to an unauthenticated attacker over the network.

  • CVE-2026-49234HIGH 7.5

    Routinator, an open-source RPKI relying party software maintained by NLnet Labs, crashes when it receives a malformed (non-UTF-8 encoded) query parameter in API requests. An attacker sending a specially crafted string to the /api/v1/origins endpoint can trigger a denial-of-service condition that takes the service offline. The vulnerability only affects deployments that expose the Routinator API to untrusted networks without additional access controls.

  • CVE-2026-49235HIGH 7.5

    Routinator, a RPKI validator from NLnet Labs, crashes when processing specially crafted XML files delivered through the RRDP protocol. An attacker can trigger this denial-of-service condition remotely without authentication, making the service unavailable to legitimate users who depend on it for RPKI validation.

  • CVE-2026-49256HIGH 7.5

    Discourse, a popular open-source discussion platform, was leaking sensitive metadata to unauthorized users. Specifically, restricted tag and tag-group names that should have been hidden were becoming visible to anonymous visitors and users without proper permissions when viewing publicly readable categories. This information disclosure occurred through the category and group API endpoints. Four patch versions address this issue across the supported release branches.

  • CVE-2026-49293HIGH 7.5

    js-toml is a JavaScript library that parses TOML configuration files. Versions up to 1.1.0 contain a performance flaw that allows attackers to freeze your application by submitting specially crafted TOML files with very large hexadecimal, octal, or binary numbers. A malicious actor could submit a ~500 KB hex number that would pin your CPU for roughly 40 seconds—enough to cause a denial of service. Any system accepting TOML uploads or parsing untrusted TOML is at risk.

  • CVE-2026-49361HIGH 7.5

    Apache Fluss, a distributed stream processing engine still in incubation at the Apache Software Foundation, contains a critical flaw in how it handles network traffic. Versions 0.8.0 and 0.9.0 allow attackers on the network to send specially crafted data packets that trick the system into consuming massive amounts of memory, causing the service to crash. No authentication is required—an attacker can do this from anywhere on the network without logging in. This is a denial-of-service vulnerability that impacts both the TabletServer and CoordinatorServer components.

  • CVE-2026-49372HIGH 7.5

    JetBrains TeamCity versions prior to 2026.1 and 2025.11.5 contain a server-side request forgery (SSRF) vulnerability accessible without authentication. An attacker can abuse the build status feature to make the TeamCity server perform unintended HTTP requests to internal or external systems, potentially exposing sensitive data or accessing restricted resources. The vulnerability requires no user interaction and can be exploited over the network.

  • CVE-2026-49432HIGH 7.5

    Apache ActiveMQ has a flaw that allows an unauthenticated attacker to crash message broker instances by sending malformed network requests through the STOMP protocol connector. By specifying a negative content-length header and streaming body data, the attacker can either exhaust memory on NIO transports or trigger a forced connection closure on blocking transports, resulting in denial of service. No authentication is required, and the attack succeeds if the STOMP port is accessible over the network.

  • CVE-2026-49434HIGH 7.5

    Apache ActiveMQ contains an input validation flaw that allows attackers with LDAP write access to inject malicious configuration. By modifying LDAP entries matching the broker's search criteria, an attacker can force the broker to instantiate unauthorized transports, retrieve external URLs, and spawn a second message broker instance within the same JVM. This effectively gives an attacker the ability to create a parallel, attacker-controlled broker alongside the legitimate one.

  • CVE-2026-49451HIGH 7.5

    The OpenAPI.NET SDK, a Microsoft library for handling OpenAPI document models in .NET applications, contains a flaw that allows a specially crafted OpenAPI document with circular schema references to crash the application. When the SDK attempts to parse such a document, it exhausts the available memory stack, terminating the process. This affects versions released between preview 11 and version 3.5.4 for the 3.x branch, and up to 2.7.5 for the 2.x branch. An attacker can trigger this denial of service by providing a malicious OpenAPI file—either in JSON or YAML format—to any system using the vulnerable SDK to parse untrusted OpenAPI documents.

  • CVE-2026-49475HIGH 7.5

    FreeSWITCH, a popular open-source telecom platform used to build VoIP and communication systems, contains a flaw in how it processes STUN packets—a protocol used for network address translation and firewall traversal in voice communications. An attacker sending a specially crafted STUN packet with a mismatched attribute length can cause the software to read and write beyond allocated memory buffers. This out-of-bounds memory access occurs in the media buffer handling logic and can crash the affected FreeSWITCH instance, disrupting voice and video services. The vulnerability affects all versions prior to 1.11.0.

  • CVE-2026-49486HIGH 7.5

    Apache Airflow's FTP provider has a critical flaw in how it establishes secure file transfers. When using FTPSHook or FTPSFileTransmitOperator, the connection setup protects the initial login channel with TLS encryption, but fails to enable encryption for the actual file data being transmitted. This means an attacker positioned on the network path between your Airflow instance and the FTP server can intercept and read file contents and any embedded credentials, despite the connection appearing secure. The vulnerability affects all versions of apache-airflow-providers-ftp prior to 3.15.1.

  • CVE-2026-49494HIGH 7.5

    A flaw in the firewall driver used by Xcitium Client Security and Comodo Internet Security allows attackers to remotely crash a computer by sending a specially crafted network packet. The vulnerability exists because the firewall driver incorrectly handles IPv6 packets when the declared payload size is smaller than the actual data it contains. This causes an integer underflow—a calculation error where a number wraps around to an extremely large value—which then causes the system to attempt to read memory far beyond safe boundaries and ultimately crash with a blue screen of death. The attack requires no authentication and can succeed even on fully firewalled systems.

  • CVE-2026-4967HIGH 7.5

    CVE-2026-4967 is a remote denial-of-service vulnerability in IMS caused by missing bounds validation during memory read operations. An attacker can remotely trigger an out-of-bounds read without authentication, causing the service to crash or become unavailable. The flaw requires only network access and no special privileges to exploit.

  • CVE-2026-49842HIGH 7.5

    FreeSWITCH, an open-source telecom platform, contains a flaw in its WebSocket handling that allows unauthenticated attackers to trigger massive outbound data transfers. An attacker can send a specially crafted speed-test protocol message that causes the server to send back approximately 20 GB of data per request, effectively amplifying a small request into a large bandwidth-consuming response. This vulnerability exists before patching and requires no authentication or user interaction—any network-connected FreeSWITCH instance is at risk.

  • CVE-2026-49847HIGH 7.5

    FreeSWITCH versions prior to 1.11.1 are vulnerable to a denial-of-service attack that can be triggered by sending a specially crafted WebSocket message containing deeply nested JSON data. An attacker requires no authentication and can crash the entire FreeSWITCH process from the network, immediately terminating all active calls and sessions on the affected host. The vulnerability exploits improper recursion handling in JSON parsing, causing a stack overflow that the kernel stops before any memory corruption can be weaponized.

  • CVE-2026-49851HIGH 7.5

    Mistune, a popular Python library for converting Markdown to HTML, contains a performance flaw that allows attackers to exhaust server CPU resources with minimal effort. The vulnerability stems from inefficient parsing logic when handling multiple consecutive opening brackets in Markdown input. By sending specially crafted Markdown documents, an attacker can force the parser to consume excessive CPU cycles, potentially causing service degradation or denial of service. This affects Mistune versions prior to 3.3.0.

  • CVE-2026-49866HIGH 7.5

    A vulnerability exists in libp2p's gossipsub implementation that allows attackers to send specially crafted network messages containing extremely large arrays of message identifiers. When the library processes these messages, it must iterate through tens of thousands of IDs synchronously, monopolizing the Node.js event loop and freezing the application. An attacker on the network can trigger this denial-of-service condition repeatedly without authentication.

  • CVE-2026-49941HIGH 7.5

    Net::CIDR::Set, a Perl library for managing IP address ranges, contains a flaw in how it parses IP addresses. When the library receives an improperly formatted IP address, instead of rejecting it, the code enters an infinite loop trying to process it. An attacker can exploit this by sending malformed input to applications using the vulnerable library, causing them to hang and become unresponsive. This is a denial-of-service vulnerability affecting versions up to and including 0.20.

  • CVE-2026-49975HIGH 7.5

    Apache HTTP Server contains a vulnerability in its mod_http module that allows attackers to crash the web server by sending specially crafted HTTP requests. The flaw stems from improper memory allocation handling—specifically, when the server attempts to allocate an excessively large block of memory in response to a malicious request, it can exhaust system resources and cause a denial of service. No user authentication is required to exploit this vulnerability, and attackers can trigger it remotely over the network. Affected versions span from 2.4.17 through 2.4.67.

  • CVE-2026-50010HIGH 7.5

    Netty, a widely-used Java framework for building networked applications, contains a vulnerability in how it handles TLS certificate validation. When developers supply their own certificate trust manager to Netty's SSL configuration, the framework wraps it in a way that causes hostname verification to be skipped entirely—even though Netty attempts to enable it by default. An attacker positioned to intercept network traffic could exploit this to perform man-in-the-middle attacks, presenting a valid certificate for a different domain and having the client accept it without complaint.

  • CVE-2026-50011HIGH 7.5

    Netty, a widely-used network framework, contains a memory exhaustion vulnerability in its Redis protocol handler. When processing incoming Redis array messages, the framework pre-allocates memory based on a count declared in the message header before validating the actual content. An attacker can send a malicious message claiming an extremely large array size, forcing the application to reserve massive amounts of memory with minimal network traffic. This causes the application to consume excessive RAM and potentially crash, denying service to legitimate users.

  • CVE-2026-50031HIGH 7.5

    FreeIPMI is a widely-used open-source toolkit for managing servers through the IPMI interface—a standard hardware management protocol used across nearly all enterprise and data-center hardware. Two specific commands in FreeIPMI versions before 1.6.18 contain buffer overflow vulnerabilities that can be exploited by sending specially crafted responses from an IPMI server. If you run `ipmi-oem dell get-active-directory-config` or `ipmi-oem fujitsu get-sel-entry-long-text` against an attacker-controlled or compromised IPMI server, those overflows can crash your system or potentially allow arbitrary code execution on the machine running the FreeIPMI client.

  • CVE-2026-50108HIGH 7.5

    Naxclow's platform API contains a flaw that leaks persistent credentials used for device relay registration. An attacker who can craft a valid API request signature can retrieve relay credentials for any device—even devices they don't own—and impersonate that device on the relay network. This enables the attacker to intercept, monitor, or disrupt communications for compromised devices without needing to breach the device itself.

  • CVE-2026-50129HIGH 7.5

    Mastodon, the open-source social network platform, contains a denial-of-service vulnerability in how it processes mathematical markup (math tags). An attacker can send specially crafted math content that causes the server to crash or become unavailable, potentially affecting either the entire Mastodon instance or specific user services. The flaw stems from missing error handling in the code that sanitizes mathematical notation. Three security updates fix this issue across Mastodon's active maintenance branches.

  • CVE-2026-50170HIGH 7.5

    Angular applications using Server-Side Rendering (SSR) with hydration are vulnerable to unintended credential caching and data leakage. When Angular's HttpTransferCache utility prepares responses for the client, it doesn't check whether those requests included credentials or sensitive cookies. This means user-specific data—like personalized account information—can end up cached in the TransferState payload that gets baked into the HTML. If a CDN, reverse proxy, or shared cache layer then caches that HTML page, the next user to request the same page could receive the previous user's private data. The vulnerability affects Angular versions prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

  • CVE-2026-50176HIGH 7.5

    CVE-2026-50176 is a flaw in the WebSocket API that fails to limit how many authentication attempts a user or attacker can make in a given time period. Without rate limiting, attackers can hammer the authentication endpoint with repeated login attempts—either to knock the service offline through sheer volume, or to systematically guess credentials. The vulnerability carries a HIGH severity rating because it directly enables denial-of-service and credential compromise attacks that require no special privileges and no user interaction to initiate.

  • CVE-2026-50193HIGH 7.5

    Jackson-databind, a widely-used Java library for converting JSON to objects and vice versa, has a denial-of-service vulnerability in versions 2.13.0 through 2.13.x. When a service uses the library to read deeply nested JSON structures (thousands of levels deep) and then serializes them back to text, an attacker can exhaust server resources by sending relatively small payloads—for example, 1000 nested arrays consume only 2 kilobytes but trigger expensive processing. The issue is fixed in version 2.14.0 and later.

  • CVE-2026-50196HIGH 7.5

    Steeltoe is a framework for building cloud-native applications on .NET, and it includes a service discovery component called Steeltoe.Discovery.Eureka. This component reads service registry information from Eureka servers—a common way microservices find each other. A bug in older versions causes the application to reject a valid service type called 'Netflix' data center, which is legitimately defined in the Eureka specification. When this happens, the registry deserialization fails silently during periodic refresh cycles, leaving your local service registry empty or out of date. This can break service-to-service communication in production environments. Updating to version 4.2.0 (or 3.4.0 for older release lines) fixes the issue.

  • CVE-2026-50200HIGH 7.5

    Steeltoe's management endpoint used for monitoring application health and configuration leaks sensitive database connection details when accessed over the network. The component responsible for hiding passwords and secrets has gaps in its pattern matching—it misses connection strings that follow standard .NET naming conventions. An attacker with network access to the monitoring endpoint can retrieve full connection strings containing usernames, passwords, and host information without authentication. Upgrading to patched versions closes this exposure.

  • CVE-2026-50210HIGH 7.5

    CVE-2026-50210 affects Acer Connect M6E 5G devices, which use a flawed encryption method that reuses the same initialization vector for AES-CBC encryption. This is a cryptographic weakness that allows attackers to decrypt sensitive data without needing the encryption key, provided they can observe encrypted traffic or stored data. Because the initialization vector is static (always zeros), an attacker who captures multiple encrypted messages can correlate patterns and recover plaintext, or replay encrypted sessions to cause unintended actions.

  • CVE-2026-50213HIGH 7.5

    A validation endpoint in Acer Connect M6E 5G firmware exposes detailed user profile information when attackers submit predictable identification strings. Instead of simply confirming whether an account exists, the endpoint returns full profile data sheets, turning a validation function into a data harvesting tool. An unauthenticated attacker can systematically crawl this endpoint by iterating through common or sequential ID values to collect user profiles at scale.

  • CVE-2026-50234HIGH 7.5

    Lyrion Music Server version 9.2.0 has a path traversal flaw that lets attackers read files they shouldn't have access to. Because the vulnerability doesn't require authentication and can be exploited over the network with minimal complexity, an attacker can craft requests to step outside the intended directory and retrieve sensitive system or application files. The flaw affects confidentiality but does not enable attackers to modify files or disrupt service.

  • CVE-2026-50254HIGH 7.5

    CVE-2026-50254 is a memory leak vulnerability in storescp that allows an attacker to remotely trigger service degradation without authentication. By sending repeated crafted connection requests, an attacker can exhaust memory until the service crashes and stops accepting new connections. Recovery requires manual operator intervention to restart the service. The vulnerability affects the default single-process deployment mode.

  • CVE-2026-50269HIGH 7.5

    AIOHTTP, a popular Python framework for building asynchronous HTTP applications, contains a vulnerability in how it processes multipart request headers. If an application accepts user-controlled input and passes it directly into the header parameters of AIOHTTP's multipart functionality, an attacker can inject malicious headers or alter request contents. This affects versions prior to 3.14.0. The vulnerability requires the application developer to use user input in a specific way—passing it to MultipartWriter.append(headers=...) or Payload.headers—making it a conditional risk rather than a universal flaw in AIOHTTP itself.

  • CVE-2026-50559HIGH 7.5

    Quarkus, a popular Java framework for cloud-native applications, has a security flaw in how it enforces access controls on HTTP paths. An attacker can bypass authorization policies by embedding encoded characters—specifically encoded semicolons (%3B), slashes (%2F), or backslashes (%5C)—in request URLs. This allows unauthorized access to protected resources and sensitive functionality that should be restricted. The vulnerability affects multiple Quarkus version branches; patched versions are available across the 3.20, 3.27, 3.33, and 3.36+ series.

  • CVE-2026-50645HIGH 7.5

    Apache CXF, a popular web services framework, does not limit the number of attachment headers it accepts when processing incoming messages. An attacker can exploit this by sending messages with an extremely large number of attachments, forcing the application to consume excessive memory and CPU resources, resulting in a denial-of-service condition. The vulnerability affects message deserialization—the process of converting data from network format back into usable objects—making it a network-level attack that requires no authentication or user interaction.

  • CVE-2026-5073HIGH 7.5

    The ARMember Premium WordPress plugin contains a SQL injection flaw in its directory member listing feature. Attackers can manipulate how results are sorted to inject malicious SQL commands, potentially stealing sensitive data from the WordPress database without needing to log in. The vulnerability affects all versions through 7.3.1.

  • CVE-2026-50734HIGH 7.5

    Apache ActiveMQ has a vulnerability in how it handles initial connection setup with clients. An attacker on the network can send a specially crafted message during the handshake phase that tricks the broker into trying to allocate an unreasonably large amount of memory. Because this validation happens before the attacker is even authenticated, they don't need credentials. If successful, the broker runs out of memory and crashes, leaving it unable to serve legitimate users. This is a straightforward denial-of-service attack that requires only network access and no special privileges.

  • CVE-2026-50750HIGH 7.5

    Apache ActiveMQ has a denial-of-service vulnerability where an unauthenticated attacker can crash the message broker by sending repeated BrokerInfo commands without establishing a proper connection. This flaw emerged as a regression after a fix for an earlier vulnerability, allowing attackers to exhaust server memory until the broker becomes unavailable. The issue affects multiple recent versions of ActiveMQ across 5.19.x and 6.2.x release lines.

  • CVE-2026-5079HIGH 7.5

    A vulnerability in the multer file upload library affects versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1. Attackers can craft a single HTTP request with deeply nested field names in form data to trigger excessive CPU and memory consumption, crashing or severely degrading the affected application. The issue stems from the append-field dependency parsing bracket notation without enforcing nesting limits. No user interaction or authentication is required to exploit this.

  • CVE-2026-50870HIGH 7.5

    A vulnerability in whoogle-search version 1.2.3 exposes sensitive configuration information through an unauthenticated web request. An attacker can craft a simple GET request to the configuration endpoint and retrieve data that should remain private, such as API keys, authentication tokens, or system settings. No special privileges or user interaction is required—the vulnerability is network-accessible and trivial to exploit.

  • CVE-2026-50877HIGH 7.5

    Zhoros SuperBin version 1.0.0 contains a directory traversal vulnerability that allows unauthenticated attackers to read files outside the intended directory boundaries. An attacker can craft specially-named files containing path traversal sequences (such as '../' characters) to navigate the file system and access sensitive files. This requires no special privileges or user interaction, making it a straightforward attack to execute remotely.

  • CVE-2026-50878HIGH 7.5

    Feuerhamster MailForm version 1.1.0 contains a vulnerability in how it handles file attachments. An attacker can send a specially crafted request to the application that causes it to become unresponsive or crash, denying legitimate users access to the service. No authentication is required to trigger this issue, and it can be exploited over the network.

  • CVE-2026-50879HIGH 7.5

    A vulnerability in the uploadPostHandler component of linx-server v2.3.8 allows remote attackers to disrupt service availability by sending specially crafted POST requests. No authentication is required, and the attack can be executed over the network from any location. The vulnerability does not expose sensitive data or enable unauthorized modifications; its primary impact is preventing legitimate users from accessing the service.

  • CVE-2026-50882HIGH 7.5

    CVE-2026-50882 is a Denial of Service vulnerability in anna-is-cute paste v0.1.1 affecting the /api/v0/pastes endpoint. An attacker can send a specially crafted POST request to crash or severely degrade the service, rendering it unavailable to legitimate users. No authentication is required, and the attack can be launched over the network from anywhere. The vulnerability does not compromise data confidentiality or integrity—only availability.

  • CVE-2026-50885HIGH 7.5

    Sismics Docs (also known as Teedy) version 1.11 contains a flaw in how it controls who can access certain file-sharing endpoints. An attacker without any credentials can craft a specially formed request to read sensitive information from the system. This is a remote attack that requires no special privileges or user interaction, making it relatively straightforward to exploit over the network.

  • CVE-2026-50889HIGH 7.5

    LLDAP version 0.6.2 contains a vulnerability in how it processes HTTP refresh tokens. An attacker can send a specially crafted refresh-token header that causes the application to stop responding, effectively taking it offline. No authentication is required—anyone with network access can attempt this attack. The vulnerability does not expose data or allow unauthorized access, but it can disrupt service availability.

  • CVE-2026-51218HIGH 7.5

    A vulnerability in snap7 v1.4.3 allows attackers to crash systems by sending specially crafted network packets. The flaw is a heap buffer overflow in a core server function that handles data writes, meaning an attacker can overflow memory buffers to trigger a denial of service without needing authentication or user interaction. The vulnerability affects any system running the vulnerable snap7 library and exposed to network traffic.

  • CVE-2026-51219HIGH 7.5

    A heap memory overflow vulnerability exists in lib60870 versions 2.3.3 through 2.3.6 that can crash systems processing certain network messages. An unauthenticated attacker on the network can send a specially crafted payload to trigger the overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function, causing service interruption. No data theft or system compromise occurs; the primary impact is availability loss.

  • CVE-2026-51221HIGH 7.5

    A buffer overflow vulnerability exists in EIPStackGroup OpENer's Get_Attribute_List function that allows attackers to crash affected systems by sending specially crafted network packets. The vulnerability requires no authentication or user interaction, making it accessible to remote attackers on the network. While the flaw does not enable data theft or unauthorized access, it can disrupt availability—a significant concern for industrial control systems and networked devices that rely on OpENer.

  • CVE-2026-51535HIGH 7.5

    OpENer 2.3.0 contains a resource exhaustion vulnerability in its network message processing loop that allows an unauthenticated attacker to send specially crafted network packets and exhaust server resources, causing a denial of service. An attacker can trigger this flaw from the network without authentication, making it accessible to anyone with network access to an affected system.

  • CVE-2026-51600HIGH 7.5

    Tenda CP3 V3.0 devices running firmware V31.1.9.91 contain a flaw in how they process streaming protocol requests. When a malicious or misconfigured client sends an RTSP request (used for media streaming) with a Content-Length header but no actual data following it, the device gets stuck waiting for that data indefinitely. The connection never closes, consuming resources on the device until all available connections are exhausted. An attacker on the network can exploit this without credentials to render the device unresponsive to legitimate requests.

  • CVE-2026-51601HIGH 7.5

    Tenda CP3 V3.0 devices running firmware V31.1.9.91 contain a denial-of-service vulnerability in their RTSP (Real Time Streaming Protocol) service. An attacker who establishes a basic RTSP connection can send a specially crafted request with an abnormally long value in a specific field, causing the RTSP service to crash and become unavailable. The vulnerability requires the attacker to complete a standard RTSP handshake first, but no authentication credentials are needed.

  • CVE-2026-51602HIGH 7.5

    Tenda CP3 V3.0 devices running firmware V31.1.9.91 contain a flaw in their RTSP (Real Time Streaming Protocol) service that allows an unauthenticated attacker on the network to crash the device by sending a specially crafted request. The vulnerability exploits a gap between two validation stages: the first stage checks basic request format, but the second stage fails to properly limit the size of URL data it processes. An attacker who sends a request containing exactly four repetitions of a valid RTSP URL can overflow a buffer in memory, immediately crashing the RTSP service and making the device unavailable to all users on that network.

  • CVE-2026-51603HIGH 7.5

    Tenda CP3 V3.0 routers running firmware V31.1.9.91 contain a vulnerability in their RTSP media streaming service that allows anyone on the network to crash the device without needing to log in. An attacker must first establish a legitimate RTSP session, then send a specially crafted second request with an oversized URL field. The flaw lies in insufficient input validation—the second parsing stage fails to check URL length properly, letting a malformed request overflow a temporary buffer on the stack. When triggered, the RTSP service immediately crashes, knocking the router offline until manually restarted and preventing all users from streaming media or accessing the device remotely.

  • CVE-2026-51604HIGH 7.5

    A stack-based buffer overflow in Tenda CP3 devices running firmware V31.1.9.91 can be triggered via a specially crafted RTSP PLAY request sent over the network. An attacker without credentials can crash the device, causing service disruption. The vulnerability affects the RTSP protocol handler and requires no user interaction to exploit.

  • CVE-2026-51605HIGH 7.5

    A stack-based buffer overflow vulnerability exists in the RTSP (Real Time Streaming Protocol) service of Tenda CP3 devices running firmware V31.1.9.991. An unauthenticated attacker on the network can send a specially crafted TEARDOWN request to trigger the overflow, causing the service to crash and become unavailable. No authentication is required, and the attack can be executed remotely, making this a practical denial-of-service vector against affected devices.

  • CVE-2026-51606HIGH 7.5

    A vulnerability in Tenda CP3 V3.0 devices (firmware V31.1.9.91) causes the RTSP service to crash and terminate connections when it receives requests with oversized field values. Instead of properly rejecting the malformed request per protocol standards, the device sends a TCP reset (RST), disrupting legitimate video streaming traffic. An attacker on the network can trigger this denial-of-service condition by sending crafted RTSP requests without authentication.

  • CVE-2026-51926HIGH 7.5

    A vulnerability in docuForm GmbH FSM Client version 11.11c allows attackers to identify valid user accounts without authentication. By submitting login attempts, an attacker can observe differences in how the system responds to existing versus non-existing usernames. This user enumeration flaw doesn't directly compromise accounts, but it significantly reduces the difficulty of subsequent attacks like password guessing or credential stuffing, making it a stepping stone to account compromise.

  • CVE-2026-51937HIGH 7.5

    Oneblog V2.3.9 contains a vulnerability that allows attackers on the network to extract sensitive information without needing credentials or user interaction. The flaw exists in three Java components responsible for API access and token management, making it a direct channel to confidential data. The vulnerability requires only network access and presents a high-severity risk to any deployment running the affected version.

  • CVE-2026-52187HIGH 7.5

    A buffer overflow flaw has been identified in UTT's nv518G device running firmware version nv518GV3v3.2.7-210919-161313. The vulnerability exists in the gohead web server component and allows an unauthenticated remote attacker to crash the device, disrupting service availability. No data theft or system compromise is possible through this defect—the risk is purely denial of service.

  • CVE-2026-52189HIGH 7.5

    A buffer overflow vulnerability exists in UTT's nv518G device running firmware version nv518GV3v3.2.7-210919-161313. An attacker on the network can exploit this flaw to crash the device without authentication or user interaction. The vulnerability affects a specific internal component and poses a denial-of-service risk to organizations relying on this equipment.

  • CVE-2026-52190HIGH 7.5

    A buffer overflow flaw in UTT's nv518G device (firmware version 3.2.7-210919-161313) can be exploited remotely to crash the device or cause it to become unresponsive. An attacker does not need to authenticate or interact with a user to trigger the vulnerability—simply sending a specially crafted network request to the gohead web service component is sufficient. While the current evidence suggests denial-of-service impact, buffer overflows carry inherent risk for more severe outcomes if exploitation techniques evolve.

  • CVE-2026-52191HIGH 7.5

    A buffer overflow vulnerability exists in UTT nv518G devices running firmware version nv518GV3v3.2.7-210919-161313. The flaw resides in the gohead web server component and can be triggered remotely without authentication, allowing an attacker to crash the device and interrupt service. No user interaction is required for exploitation.

  • CVE-2026-52192HIGH 7.5

    CVE-2026-52192 is a remote denial-of-service vulnerability affecting UTT nv518G devices running firmware version nv518GV3v3.2.7-210919-161313. An unauthenticated attacker on the network can trigger a crash or service outage by sending specially crafted requests to the gohead component, rendering the affected device unavailable until manual intervention restores it.

  • CVE-2026-52193HIGH 7.5

    A buffer overflow vulnerability exists in UTT nv518G devices running firmware version nv518GV3v3.2.7-210919-161313. An attacker on the network can send specially crafted requests to trigger the overflow condition, resulting in denial of service. The vulnerability requires no authentication and can be exploited remotely, making it a significant risk for organizations deploying these devices.

  • CVE-2026-52195HIGH 7.5

    A buffer overflow vulnerability exists in UTT nv518G devices running firmware version nv518GV3v3.2.7-210919-161313. A remote attacker can exploit this flaw in the gohead component to crash the device, causing denial of service. No authentication is required to trigger the vulnerability, and it can be attacked over the network without user interaction.

  • CVE-2026-52196HIGH 7.5

    A buffer overflow vulnerability in the UTT nv518G device (firmware version nv518GV3v3.2.7-210919-161313) allows attackers to remotely crash the device. An attacker on the network can send specially crafted input to the gohead component without any special privileges or user interaction, causing the device to become unresponsive. This is a denial-of-service issue—attackers cannot steal data or gain control, but they can disrupt service availability.

  • CVE-2026-52197HIGH 7.5

    A vulnerability in UTT nv518G firmware version 3.2.7-210919-161313 allows attackers on the network to crash or disable the device by sending specially crafted requests to the gohead web component. No authentication is required, and the attack can be performed remotely. This is a denial-of-service flaw that could interrupt service availability for organizations relying on this equipment.

  • CVE-2026-52198HIGH 7.5

    A buffer overflow vulnerability exists in UTT nv518G devices running firmware version nv518GV3v3.2.7-210919-161313. An attacker on the network can send specially crafted requests to exploit this flaw and potentially disrupt the device's operation. The vulnerability requires no authentication or user interaction, making it accessible to any remote attacker.

  • CVE-2026-52694HIGH 7.5

    The Signature Add-On for WooCommerce, in versions 2.0 and earlier, exposes sensitive data to unauthenticated users. An attacker can access confidential information without needing credentials or authentication. The vulnerability is network-accessible, requires no special configuration, and can be exploited remotely. This is a significant exposure risk for any WooCommerce installation using this plugin.

  • CVE-2026-52726HIGH 7.5

    Dulwich, a Python library that implements Git functionality, contains a critical flaw in how it handles submodules from untrusted repositories. When cloning a repository with submodules enabled, or when explicitly updating submodules, the library fails to validate where those submodules are being placed. An attacker can craft a malicious repository with a `.gitmodules` file that points a submodule to a path like `.git/hooks/`, causing arbitrary files to be written into your repository's hook directory. Since Git automatically runs hooks during normal operations, this allows the attacker to execute code on your system. The vulnerability affects Dulwich versions 0.23.2 through 1.2.4.

  • CVE-2026-52794HIGH 7.5

    Sentry, a widely-used error tracking and performance monitoring platform, contains a flaw in how it processes incoming event data. Attackers can craft malicious events with specially formatted fields that cause Sentry's regex pattern matching to consume excessive CPU resources, potentially overwhelming the service. This denial-of-service impact affects Sentry instances running versions 24.4.0 through 26.5.1. The vulnerability has been patched in version 26.5.2.

  • CVE-2026-52799HIGH 7.5

    Gogs, a self-hosted Git service, contains an authorization bypass vulnerability affecting versions before 0.14.3. An attacker can download file attachments from private repositories without proper authentication or permission checks. The vulnerability exists because the endpoint serving attachments (GET /attachments/:uuid) does not validate whether the requester has access to the associated Issue, Comment, Release, or repository. In environments configured to allow unauthenticated access, this exposes sensitive attached files to unauthorized parties.

  • CVE-2026-52844HIGH 7.5

    Caddy, a popular web server platform, has a flaw in how it handles file paths on Windows systems. When a client requests a file using mixed path separators (like /private\secret.txt), Caddy's security rules incorrectly think the request is outside a protected directory, but the actual file serving code resolves it to the correct file anyway. This means an attacker can bypass authentication or access denial rules that are meant to protect sensitive files. The issue only affects Windows deployments running Caddy before version 2.11.4.

  • CVE-2026-52922HIGH 7.5

    A bug in the Linux kernel's batman-adv networking module can crash systems when memory allocation fails during DHT (Distributed Hash Table) forwarding operations. When the kernel tries to duplicate network packets for wireless mesh routing, it doesn't check if the duplication succeeded before trying to use the packet. If memory is scarce and duplication fails, the code attempts to process a NULL pointer, causing a kernel panic. This affects systems using batman-adv, typically mesh networks and certain wireless setups.

  • CVE-2026-52929HIGH 7.5

    A flaw in the Linux kernel's SCTP (Stream Control Transmission Protocol) implementation causes incomplete cleanup when an application attempts to add outgoing streams but the operation is denied. The kernel removes some metadata but leaves behind stale stream configuration data. When the application later tries to add streams again, the kernel reuses this leftover data incorrectly, leading to a null-pointer dereference that crashes the system. The fix ensures that denied stream-addition requests are fully rolled back, cleaning up all associated state to prevent the crash.

  • CVE-2026-52932HIGH 7.5

    A memory management flaw has been discovered in the Linux kernel's IPsec compression (xfrm/ipcomp) subsystem. When the asynchronous compression function encounters an error, the kernel fails to properly release memory allocated for destination buffer pages, causing a memory leak. This issue is fixed by adjusting the error handling path to ensure cleanup occurs in all failure scenarios.

  • CVE-2026-52945HIGH 7.5

    A vulnerability in the Linux kernel's WireGuard implementation causes network traffic decryption to stall and become unresponsive under certain conditions. When WireGuard processes incoming encrypted data for decryption, a race condition in the packet handling logic can cause the decryption queue to fill completely, blocking all further decryption for a specific peer connection while other peers continue working normally. Once triggered, the affected peer remains stuck until the system is restarted, even though CPU and memory appear healthy. This issue stems from a 2023 kernel change that switched WireGuard to use threaded NAPI (Network API), and has been observed in production Kubernetes clusters using Cilium with WireGuard encryption.

  • CVE-2026-52946HIGH 7.5

    A deadlock vulnerability exists in the Linux kernel's file access signaling code. When a process group receives a signal via FASYNC (asynchronous I/O notification), the kernel can deadlock under specific conditions. The issue arises because the code uses a read lock on the task list while running in softirq context (a special kernel interrupt handler), but a writer somewhere else may be waiting to acquire that same lock. This creates a circular wait: the softirq handler is blocked trying to read-lock a resource, while a writer is spinning and preventing new readers. The vulnerability can be triggered remotely via TCP URG (urgent) packets, making it a potential denial-of-service vector without requiring authentication or user interaction.

  • CVE-2026-52954HIGH 7.5

    A flaw in the Linux kernel's Ceph cluster storage client allows a malicious or corrupted OSD map message to crash the system. When the Ceph protocol processes cluster topology updates, it can decode optional routing data called choose_args. If an attacker sends a crafted message containing duplicate routing indices, the kernel hits an unprotected assertion and crashes. This is a denial-of-service vulnerability that requires network access to a Ceph cluster but no special privileges.

  • CVE-2026-52956HIGH 7.5

    A flaw in the Linux kernel's Ceph network communication library allows an attacker to read beyond the boundaries of a memory buffer when processing encrypted messages. An incoming message with insufficient data can cause the decryption function to access memory outside the buffer's allocated space, leading to a denial of service. This affects systems using Ceph for distributed storage or cluster communication.