Strobes VIStrobes VI
CVE DatabaseThreat ActorsResearchAPI Docs
Visit Strobes.coSign Up for Strobes
CVE DatabaseThreat ActorsResearchAPI Docs
Tools
KB Lookup
Visit Strobes.coSign Up for Strobes

Do you like the insights?

Strobes vulnerability intelligence is a key component of their Exposure Management platform that helps organizations understand, prioritize, and address security vulnerabilities more effectively.

© 2026 Strobes Security. All rights reserved.
HomeExplore CVEs

Explore CVEs

Filter and search through 392,252 vulnerabilities

Filters
0
01000
Showing 20 of 392,252 results
CVE IDDescriptionCVSSPriorityTrendExploitPatch
CVE-2026-23967

### Summary A signature malleability vulnerability exists in the SM2 signature verification logic of the sm-crypto library. An attacker can derive a ...

7.5386NeutralNo
Page 15
PreviousNext
Yes
CVE-2026-23966

### Summary A private key recovery vulnerability exists in the SM2 decryption logic of sm-crypto. By interacting with the SM2 decryption interface mu...

9.1568NeutralNoYes
CVE-2026-23965

### Summary A signature forgery vulnerability exists in the SM2 signature verification logic of sm-crypto. Under default configurations, an attacker ...

7.5386NeutralNoYes
CVE-2026-23964

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object ref...

6.5224NeutralNoNo
CVE-2026-23963

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, the server does not enforce a...

4.3107NeutralNoNo
CVE-2026-23962

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, and v4.5.5 do not have a limit ...

7.5394NeutralNoNo
CVE-2026-23961

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows server administrators to suspend remote users to prevent i...

5.3132NeutralNoNo
CVE-2026-23960

### Summary Stored XSS in the artifact directory listing allows any workflow author to execute arbitrary JavaScript in another user’s browser under th...

0.00NeutralNoYes
CVE-2026-23959

# SQL Injection in CustomerTransformerController ## Summary An **error-based SQL Injection vulnerability** was identified in the `CustomerTransformer...

0.00NeutralNoYes
CVE-2026-23958

Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT si...

0.00NeutralNoNo
CVE-2026-23957

Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to **significantly increase proc...

7.5386NeutralNoYes
CVE-2026-23956

Overriding RegExp serialization with extremely large patterns can **exhaust JavaScript runtime memory** during deserialization. Additionally, overridi...

7.5386NeutralNoYes
CVE-2026-23955

EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated to literal strings when throwi...

4.290NeutralNoNo
CVE-2026-23954

### Summary A user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) can use directory traversal or symbo...

8.7662NeutralNoYes
CVE-2026-23953

### Summary A user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environme...

8.7539NeutralNoYes
CVE-2026-23952

## Summary NULL pointer dereference in MSL (Magick Scripting Language) parser when processing `<comment>` tag before any image is loaded. ## Version...

6.5209NeutralNoYes
CVE-2026-23951

SumatraPDF is a multi-format reader for Windows. All versions contain an off-by-one error in the validation code that only triggers with exactly 2 rec...

5.5133NeutralNoNo
CVE-2026-23950

**TITLE**: Race Condition in node-tar Path Reservations via Unicode Sharp-S (ß) Collisions on macOS APFS **AUTHOR**: Tomás Illuminati ### Details A...

8.8545NeutralNoYes
CVE-2026-2395

No description available

0.00NeutralYesNo
CVE-2026-23949

### Summary There is a Zip Slip path traversal vulnerability in the jaraco.context package affecting setuptools as well, in `jaraco.context.tarball()`...

8.6659NeutralNoYes