57,566 vulnerabilities published in 2026
SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar
Improper authorization in the Intel(R) Quick Assist Technology for some Intel(R) Platforms within Ring 0: Kernel may all
Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, c
On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a netwo
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose informatio
The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what
Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents
Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.
An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo
Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may al
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrap
The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5,
The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all ve
The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that r
The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthentic
The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 th
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains
An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accoun
An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user acc
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th
An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gain
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, th
A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remot
Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform U
Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cros
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who c
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinc
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started