57,566 vulnerabilities published in 2026
Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0.
A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. Users are recommended
Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4
A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended
When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause
"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie
Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys
Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacke
Our payment integration with Computop-based payment methods did not properly validate payment status responses. An atta
Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization o
Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF
Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since
Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src
Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a success
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Intercepti
Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b
Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsin
SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptogra
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patch
An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access t
A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can exe
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)
HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The functi
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the ac
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto
Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in
The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled,
SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but ex
Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verifica
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx all
Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause
Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.
Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker wh
Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scri
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started