57,566 vulnerabilities published in 2026
OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hij
Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOL
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported ve
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported ve
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran
Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain
Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypas
CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticate
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated qu
re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp
gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 unti
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf
Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192,
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:z
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into
Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function
A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
Gitea SSH Key Parser Denial of Service
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view
Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect
Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerabili
Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerabil
Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability m
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a us
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Anothe
VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to
Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started