57,566 vulnerabilities published in 2026
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated rem
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token dec
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON wit
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download
A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissi
A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attacke
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary
A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is v
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Emai
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated at
ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application deni
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service o
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthe
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint th
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-cre
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent
ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to instal
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointe
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started