57,566 vulnerabilities published in 2026
Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token
Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint
Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9
Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through
facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_jso
OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that a
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows u
Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate th
Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain
An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated us
Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `R
Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a
Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSR
Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system,
STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Infor
A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism
An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter s
A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without an
A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only
A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v
AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the va
P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted network
SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a d
An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownershi
An improper handling of the length parameter inconsistency vulnerability has been identified in Moxa’s Secure Router. Be
OPPO Wallet APP contains a trusted domain validation flaw that allows attackers to bypass protected interface access res
Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importin
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floa
authd prior to version 0.6.4 contains a logic error in primary group ID assignment that can lead to local privilege esca
An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled
mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the ap
mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the back
mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access
A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by tri
SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/ge
This vulnerability exists in e-Sushrut due to improper authentication logic that relies on client-side response paramete
This vulnerability exists in e-Sushrut due to exposure of OTPs in plaintext within API responses. A remote attacker coul
This vulnerability exists in e-Sushrut due to improper access control in resource access validation. An authenticated at
This vulnerability exists in e-Sushrut due to improper authorization checks during resource access. An authenticated att
This vulnerability exists in e-Sushrut due to the use of reversible Base64 encoding for protecting sensitive data. An au
This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in c
Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The succe
JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @AP
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia
Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate
Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-sta
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhau
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started