57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Handle torn-down topology gracefully in
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's
In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL function pointer derefer
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix address space mismatch in kexec comm
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use kvzalloc to allocate struct dc
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fit paired fragment job in the cor
In the Linux kernel, the following vulnerability has been resolved: smp: Make CSD lock acquisition atomic for debug mod
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix possible NULL-pointer deref
In the Linux kernel, the following vulnerability has been resolved: net/sched: Handle TC_ACT_REDIRECT from qdisc filter
In the Linux kernel, the following vulnerability has been resolved: hwmon: (gigabyte_waterforce) Stop device IO before
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix NULL dereference in ffa_part
In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_range source with sr
In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag c
In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root in
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenti
Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authentica
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated att
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crat
A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter
An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to S
Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac
Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization
In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsin
Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (cu
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked
The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-dr
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service
The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose ki
The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the ope
In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's ku
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane co
Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts u
Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/
Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builde
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/u
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on U
Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop i
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/w
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit
Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS ge
Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline install
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cro
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started