57,566 vulnerabilities published in 2026
An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versio
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou
An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrar
Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote
Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap co
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security f
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be
In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized fo
An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi
Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async,
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t
Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions.
DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a
Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function
AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows aut
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()
The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards Serv
Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.Act
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e
Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,
Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 51
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, an
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the
Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automati
The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML a
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t
An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via
A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat
Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.
n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances confi
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skippe
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Str
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started