57,566 vulnerabilities published in 2026
Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker w
Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker t
Insufficient validation of untrusted input in Shortcuts in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote
Side-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to
Insufficient policy enforcement in Navigation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attack
Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-o
Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cros
Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensit
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structur
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulne
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulne
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large v
sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/cor
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory d
In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from t
CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instabil
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in
A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS applica
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local Fil
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. T
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when cr
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory g
OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers
Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Serv
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileg
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 t
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had co
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attac
SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10.
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, Fo
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted reque
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disc
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users t
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started