57,566 vulnerabilities published in 2026
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splittin
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd
Microsoft Defender Denial of Service Vulnerability
Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause i
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Insecure Storage of Sensitive Information vulnerability. An un
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c t
A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlie
XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_s
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a
Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows ex
Dräger Atlan A350 versions 1.00 up to and including 1.01 contains an improper input handling vulnerability that allows a
Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that al
Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to
Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also c
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandl
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP reques
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT
EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resul
n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may af
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk
Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in
Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_
Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to p
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo
Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could r
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affe
Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affe
Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteo
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript i
An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length
openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, al
Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privileg
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started