57,566 vulnerabilities published in 2026
A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the se
A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete ar
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic
Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a netw
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacen
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started