57,566 vulnerabilities published in 2026
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privile
Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute co
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker t
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows
Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privil
Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execut
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Enc
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses determin
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.uti
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced
GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not
CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse
Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers t
Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attack
The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero lengt
In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid deadlock on fallback while reinjecting
In the Linux kernel, the following vulnerability has been resolved: erspan: Initialize options_len before referencing o
In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use req->iv after crypto_aea
In the Linux kernel, the following vulnerability has been resolved: smc91x: fix broken irq-context in PREEMPT_RT When
A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working d
The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unau
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serviceName parameter of the sub_65A28 function
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the serverName parameter of the sub_65A28 function.
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli
Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete inst
The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the ris
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the cloneType parameter of the sub_65B5C function.
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the wanSpeed parameter of the sub_65B5C function. T
AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the ser
Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrar
Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by
GLPI is a free asset and IT management software package. Prior to 10.0.21 and 11.0.3, an unauthorized user can access GL
Directory traversal vulnerability in Omnispace Agora Project before 25.10 allowing unauthenticated attackers to read fil
GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQ
A buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Serv
An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the mac parameter of the sub_65B5C function. This v
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injecti
A stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started