57,566 vulnerabilities published in 2026
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a netw
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to
Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacen
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i
An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view
OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only
CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the d
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/appli
Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow
Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within
The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLL
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started