57,566 vulnerabilities published in 2026
Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbit
Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced
Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to in
Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the
Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources.
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic
The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a pas
Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbi
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrar
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes
Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the S
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenS
Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the who
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the app
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker t
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow i
A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denia
A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allo
A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attack
An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated att
Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered to contain a stack overflow in the Go param
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started