57,566 vulnerabilities published in 2026
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing
If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root dire
Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a cert
The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr st
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attacke
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.
An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterfac
A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private ke
An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access t
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication
An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file rea
An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discov
Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but p
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerabilit
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-a
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.
SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive informatio
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose inform
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose informati
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacke
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security fea
Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a netw
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint ret
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediatio
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14
Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the nextPage parameter to goform/formLanguageChange.
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the webPage parameter to goform/formSetWanPPTP.
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formVirtualServ.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started