57,566 vulnerabilities published in 2026
A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a n
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker t
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att
Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re
Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypasse
Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver addr
Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and
Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessiv
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on a
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the B
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulne
The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. Th
CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.
Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.
Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access
An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a direc
Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configur
Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to e
Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and belo
MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers
The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within
The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptog
The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the
The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection vi
JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to up
A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transpor
free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the han
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used t
Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unau
Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server. In a setup where OpenID
A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially
Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitr
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive fil
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started