57,566 vulnerabilities published in 2026
Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitra
When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali
As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers.
Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This
An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose e
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read in smb2_ioctl_query_info
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: move wake reason storage into
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix potential out-of-bounds rea
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF cras
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) cal
collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow
The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3
School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote att
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is
phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_ser
Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas expose
Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS o
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access t
Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticate
Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exist
A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under spe
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2
Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import fea
Inappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to pe
Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sen
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potenti
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One B
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to cr
Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed
Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume th
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (de
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT sess
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges ove
DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login han
The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated u
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started