57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: net: ngbe: fix NULL pointer dereference in non-MSI-
In the Linux kernel, the following vulnerability has been resolved: veth: fix queue index used to wake the peer txq in
In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: avoid deadlock when canceling IRQ affini
In the Linux kernel, the following vulnerability has been resolved: ovpn: defer key slot crypto freeing to workqueue K
In the Linux kernel, the following vulnerability has been resolved: ovpn: fix NULL dereference when killing missing key
In the Linux kernel, the following vulnerability has been resolved: ceph: fix hanging __ceph_get_caps() with stale mds_
In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path
Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was alread
Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same
In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null poi
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthentica
An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR c
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitra
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new F
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spr
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite att
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by inc
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthen
Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which con
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of S
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows atta
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS)
An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket
A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `
An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource:
Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch
AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extr
openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metada
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting
openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples f
openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attack
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI bl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started