57,566 vulnerabilities published in 2026
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied vi
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allo
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of serv
An integer overflow in the SMF component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via suppl
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisio
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public shar
An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attacke
An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denia
An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attacke
An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows atta
Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A
A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web manag
A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An at
Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access
The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout m
The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all vers
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured im
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to,
In the Linux kernel, the following vulnerability has been resolved: net: emac: Fix NULL pointer dereference in emac_pro
In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject compressed segment that overflow
In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: fix unaligned memory access in
In the Linux kernel, the following vulnerability has been resolved: ipv6: guard against possible NULL deref in __in6_de
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iblock: Fix wrong PR ops NULL check f
In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): i
In the Linux kernel, the following vulnerability has been resolved: sctp: validate Adaptation Indication parameter leng
In the Linux kernel, the following vulnerability has been resolved: iomap: add a separate bio_set for iomap_split_ioend
An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresse
An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenti
An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as te
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when de
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule n
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-cont
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experim
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunction
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a C
vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMed
An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of
An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic
An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the P
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started