57,566 vulnerabilities published in 2026
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` val
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map witho
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim che
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Informati
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerabilit
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `A
`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM
The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQ
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to d
An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, crea
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_c
In the Linux kernel, the following vulnerability has been resolved: smb: client: validate DFS referral PathConsumed pa
OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 exten
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to u
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the graf
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace ad
Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from int
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requ
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/val
: Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthoriz
: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (deve
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion beca
Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch an
OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Public-only repository tokens can update private PR head branches
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0,
IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with t
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the serve
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started