57,566 vulnerabilities published in 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 an
Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware versio
Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of
Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry an
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack
Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This i
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pand
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() meth
The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier
The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing compone
Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS S
A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0
The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserializa
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent n
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker t
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers t
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path t
Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbi
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write ca
Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated
ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv
The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in
An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configu
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated
A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authentic
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables u
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started