57,566 vulnerabilities published in 2026
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in
Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c wh
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsi
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuff
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server t
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildca
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as a
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a th
Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/c
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_a
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/clie
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.
Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in
Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and Pe
An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active
NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled c
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF proc
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahd
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE de
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unus
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote at
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated r
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload
TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unesca
TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect follo
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point
Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() f
A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulne
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to cre
Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC
Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenti
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata
Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoof
XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu
XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vu
A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-ST
A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 docum
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86
Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass m
A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be ret
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started