57,566 vulnerabilities published in 2026
Windows TCP/IP Denial of Service Vulnerability
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a S
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl
Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies wer
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflo
Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.
Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method V
Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker
FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_w
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who
In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buf
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0,
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb's deny_remot
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames t
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privileg
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP fronte
GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h
Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows rem
Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by
SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (mi
A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di
Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properti
Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote a
Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data vi
Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensit
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacke
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cau
Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username i
In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp()
Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference
Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacke
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client
Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Custome
update_disk_psu_baseline.sh requires password in plain text
In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated ag
Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar w
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started