57,566 vulnerabilities published in 2026
Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may
Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue
OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/applicati
Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerabil
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulne
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote
An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote
A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issu
PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attack
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is parti
In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Ve
Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via t
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attacke
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio
Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by mea
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of p
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-o
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigge
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 thr
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.
DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump file
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths withi
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a con
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unau
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over
Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service
Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a ne
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a netwo
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over
Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny servi
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to de
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses lo
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER a
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and expon
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started