Strobes VIStrobes VI
CVE DatabaseThreat ActorsResearchAPI Docs
Visit Strobes.coSign Up for Strobes
CVE DatabaseThreat ActorsResearchAPI Docs
Tools
KB Lookup
Visit Strobes.coSign Up for Strobes

Do you like the insights?

Strobes vulnerability intelligence is a key component of their Exposure Management platform that helps organizations understand, prioritize, and address security vulnerabilities more effectively.

© 2026 Strobes Security. All rights reserved.
HomeExplore CVEs

Explore CVEs

Filter and search through 392,252 vulnerabilities

Filters
0
01000
Showing 20 of 392,252 results
CVE IDDescriptionCVSSPriorityTrendExploitPatch
CVE-2026-24332

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the respon...

4.3107NeutralNo
Page 12
PreviousNext
No
CVE-2026-24307

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

9.3577NeutralNoNo
CVE-2026-24306

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

9.8741NeutralYesNo
CVE-2026-24305

Azure Entra ID Elevation of Privilege Vulnerability

9.3627NeutralNoNo
CVE-2026-24304

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

9.9636NeutralNoNo
CVE-2026-24140

MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settin...

2.792NeutralNoNo
CVE-2026-24139

MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, all...

0.00NeutralNoNo
CVE-2026-24138

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below contain an unauthenticated SSRF vul...

7.5394NeutralNoNo
CVE-2026-24137

## Summary The legacy TUF client `pkg/tuf/client.go`, which supports caching target files to disk, constructs a filesystem path by joining a cache ba...

5.8260NeutralNoYes
CVE-2026-24136

Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct ...

0.00NeutralNoNo
CVE-2026-24132

I am reporting a code injection vulnerability in Orval’s mock generation pipeline affecting @orval/mock in both the 7.x and 8.x series. This issue is ...

0.00NeutralNoYes
CVE-2026-24131

### Summary When pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root...

0.00NeutralNoYes
CVE-2026-24130

### Impact Instances of Moonraker configured with the `ldap` component enabled are vulnerable to LDAP search filter injection techniques via the logi...

0.00NeutralNoYes
CVE-2026-24129

Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versions 3.7.0 and above allow an a...

8.0467NeutralNoNo
CVE-2026-24128

### Impact A reflected cross site scripting (XSS) vulnerability in XWiki allows an attacker to execute arbitrary actions in XWiki with the rights of t...

0.00NeutralNoYes
CVE-2026-24127

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the lo...

5.4129NeutralNoNo
CVE-2026-24124

## Summary Dragonfly Manager's Job REST API endpoints lack authentication, allowing unauthenticated attackers to create, query, modify, and delete jo...

0.00NeutralNoYes
CVE-2026-24123

### Summary BentoML's `bentofile.yaml` configuration allows path traversal attacks through multiple file path fields (`description`, `docker.setup_sc...

7.4483NeutralNoYes
CVE-2026-24117

## Summary `/api/v1/index/retrieve` supports retrieving a public key via a user-provided URL, allowing attackers to trigger SSRF to arbitrary interna...

5.3253NeutralNoYes
CVE-2026-24116

On x86-64 platforms with AVX Wasmtime's compilation of the `f64.copysign` WebAssembly instruction with Cranelift may load 8 more bytes than is necessa...

0.00NeutralNoYes