57,566 vulnerabilities published in 2026
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. ChatterBot versions up to 1.2.10
SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted s
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cau
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Sui
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is tr
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the
In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), a memory leak occurs due to the broker's failu
NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a
NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through co
A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freein
A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unha
We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable wh
A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attacker
A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e
A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attacke
An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive informati
A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCall
Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrie
Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Mi
Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Cap
Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported v
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 thro
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetWifiMacFilte
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the deviceList parameter of the formSetMacFilterCfg
Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow in the ssid parameter of the form_fast_setting_wifi_se
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the time parameter of the sub_60CFC function. This
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_72290 function. Th
Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow in the security_5g parameter of the sub_727F4 function.
NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files
Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers
Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files a
ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating mult
GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability in the input field that allows attackers to cras
GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the app
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the GGUF decoder
An issue in ollama v.0.12.10 allows a remote attacker to cause a denial of service via the fs/ggml/gguf.go, function rea
Claude Code is an agentic coding tool. Prior to version 2.0.65, vulnerability in Claude Code's project-load flow allowed
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started