57,566 vulnerabilities published in 2026
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al
XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) h
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root execut
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l
free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generati
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusRea
Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large
The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressi
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSd
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH bac
A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 conn
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domai
A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when usin
Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthentica
nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingCon
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStor
pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScri
The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some P
OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-e
OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC u
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Exte
OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CON
OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that
OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attac
OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers
OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Aut
OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allow
OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Bas
A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all adm
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NT
The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file owne
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization
The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0.
The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started