57,566 vulnerabilities published in 2026
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges wi
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a phy
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a p
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attac
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-acces
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:re
Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v
A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.
Vulnerability in the PeopleSoft Enterprise CS Financial Aid product of Oracle PeopleSoft (component: Commonline Loans).
Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Security). The
Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Internal Operations). Suppor
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Repor
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Th
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported ve
Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of th
Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through e
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMA
A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API,
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one
Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository
pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol me
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox ca
Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabilit
Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabili
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when
Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and
Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to
The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an H
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able
Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-loc
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started