57,566 vulnerabilities published in 2026
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dire
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string arg
Access control failure means that an application does not effectively check user access permissions, so that unauthorize
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload_size
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client m
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth mess
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound
In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data(
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplyi
Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account
In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLRe
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic
Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Opera
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and
The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui
The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an
An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthe
Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") show
Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Sec
Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin pri
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync
In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incom
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Jav
The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458)
Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cros
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a netwo
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitis
An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory t
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate t
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the che
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to
An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu
The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PU
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd p
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex X
The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started