Every CVE of the last six months, updated daily.
Published vulnerabilities straight from the National Vulnerability Database, with severity, CWE class and affected products. Search it, filter it, and see what landed today.
- 461 published in the last 24 hours
- 2,426 in the last 7 days
- 58,761 in the last six months
Source: NVD (National Vulnerability Database) · Updated Sep 24, 2026
Showing 2 of 2
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
CWE-394libexpat_project libexpat
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.