57,566 vulnerabilities published in 2026
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitiv
A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially cr
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_mes
mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug
A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allow
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially s
decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file
Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclos
Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized atta
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a cra
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause alloc
NVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker co
NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a re
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sen
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on
pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python
OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hij
Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOL
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain
Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypas
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticate
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated qu
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf
Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192,
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:z
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started