57,566 vulnerabilities published in 2026
Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege
mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allo
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Inform
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker
OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simpl
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirk
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newslet
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-cop
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacke
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary co
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in t
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=*
Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the en
Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest u
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primit
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to imprope
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the act
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' E
In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bo
In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id fr
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks unde
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration fo
Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting
Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability th
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to wri
Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).
Vulnerability in the PeopleSoft Enterprise SCM eProcurement product of Oracle PeopleSoft (component: Manage Requisition
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started