57,566 vulnerabilities published in 2026
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged act
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Incorrect Access Control. The device exposes
Hiseeu C90 v5.7.15 is vulnerable to Insecure Permissions. The UART bootloader is accessible when battery is disconnected
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and
Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu
Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnera
Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A rem
A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsAction
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerabi
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey".
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switc
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas
Insufficient Validation of Names During AXFR
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove pass
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability ex
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for des
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and p
A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an ove
Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa
Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook serv
Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjec
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12,
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/ov
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null c
Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability
An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versio
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou
An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrar
Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote
Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap co
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security f
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be
In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized fo
An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi
Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async,
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t
Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started