57,566 vulnerabilities published in 2026
TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sendi
Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by man
MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the applica
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to
sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability ex
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supp
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,
A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.
JUNG Smart Visu Server 1.1.1050 contains a denial of service vulnerability that allows unauthenticated attackers to remo
An unauthenticated attacker can exploit this vulnerability by manipulating URL to achieve arbitrary file read access.Thi
An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, F
p2r3 bareiron commit: 8e4d4020d contains an Out-of-bounds Read, which allows unauthenticated remote attackers to get rel
p2r3 Bareiron commit: 8e4d4020d is vulnerable to Buffer Overflow, which allows unauthenticated remote attackers to cause
TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the
thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating
A stack overflow in the ZBarcode_Encode function of Monkeybread Software MBS DynaPDF Plugin v21.3.1.1 allows attackers t
A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSIO
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managi
Yoke is a Helm-inspired infrastructure-as-code (IaC) package deployer. In 0.19.0 and earlier, a vulnerability exists in
Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Re
ntpd-rs is a full-featured implementation of the Network Time Protocol. Prior to 1.7.1, an attacker can remotely induce
Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable a
XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to
FTP Navigator 8.03 contains a denial of service vulnerability that allows attackers to crash the application by overwrit
SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows atta
Bullwark Momentum Series JAWS 1.0 contains a directory traversal vulnerability that allows unauthenticated attackers to
PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration
GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the password input field that allows attackers to c
SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to c
iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash th
Centova Cast 3.2.12 contains a denial of service vulnerability that allows attackers to overwhelm the system by repeated
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u
An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a den
A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of
An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability
A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.
A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems
A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the
A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises
The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions
The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all vers
The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up
In the Linux kernel, the following vulnerability has been resolved: libceph: reset sparse-read state in osd_fault() Wh
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started