57,566 vulnerabilities published in 2026
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized att
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing o
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a networ
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a netwo
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose in
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_m
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass t
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensi
Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensiti
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same ori
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attac
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 3.1.1, @sigstore/verify deriv
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, m
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::g
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Ser
An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan
n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members
Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in
DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availabilit
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow acc
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist wh
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior
Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provide
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started