57,566 vulnerabilities published in 2026
Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.
The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of Pc
NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows au
A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35
A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0,
Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service
Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Impro
GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrai
A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated
decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and
A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in s
OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/confi
PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths
PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read f
Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb
AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to cr
AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to
SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database
The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kerne
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to dis
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose in
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to dis
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthori
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorize
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locall
Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.
Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypas
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information
Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authori
Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started