MEDIUM5.3CVE-2024-8508EPSS 0.16%CPU exhaustion during message encoding due to O(n²) name compression
MEDIUM6.6CVE-2026-41411EPSS 0.14%Vim is an open source, command line text editor.
MEDIUM6.5CVE-2026-40199EPSS 0.01%Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass.
MEDIUM4.4CVE-2026-34757EPSS 0.01%LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files.
MEDIUM6.2CVE-2026-39316EPSS 0.02%OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems.
MEDIUM6.2CVE-2026-39314EPSS 0.02%OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems.
MEDIUM5.3CVE-2026-34979EPSS 0.03%OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems.
MEDIUM6.5CVE-2026-34978EPSS 0.03%OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems.
MEDIUM4.7CVE-2026-27456EPSS 0.01%util-linux is a random collection of Linux utilities.
MEDIUM6.3CVE-2026-27447EPSS 0.01%OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems.
MEDIUM5.3CVE-2026-34743EPSS 0.06%XZ Utils provide a general-purpose data-compression library plus command-line tools.
MEDIUM6.5CVE-2026-25834EPSS 0.02%Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
MEDIUM5.9CVE-2026-21717EPSS 0.03%A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially p…
MEDIUM5.3CVE-2026-21714EPSS 0.02%A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow…
MEDIUM5.9CVE-2026-21713EPSS 0.01%A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timin…
MEDIUM5.3CVE-2026-34073EPSS 0.01%cryptography has incomplete DNS name constraint enforcement on peer names
MEDIUM5.3CVE-2026-27860EPSS 0.04%If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.
MEDIUM5.3CVE-2026-27859EPSS 0.03%A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU.
MEDIUM5.9CVE-2026-27856EPSS 0.03%Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack.
MEDIUM5.9CVE-2026-27855EPSS 0.04%Dovecot OTP authentication is vulnerable to replay attack under specific conditions.
MEDIUM4.3CVE-2025-59031EPSS 0.02%Dovecot has provided a script to use for attachment to text conversion.