57,566 vulnerabilities published in 2026
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re
Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had comprom
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr
The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before
Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect av
Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Mana
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a ph
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote att
An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthe
Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before stor
Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated rem
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authe
Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r
Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da
Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider an
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, a
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host he
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unau
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, ma
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:s
CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercep
Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the re
Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker
Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromise
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi
The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack
OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/m
Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started