57,566 vulnerabilities published in 2026
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into
Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function
A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
Gitea SSH Key Parser Denial of Service
Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view
Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect
Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerabili
Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerabil
Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability m
openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last st
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a us
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Anothe
VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to
Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes
In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to
openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set m
openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limi
The Logo Slider WordPress plugin before 4.9.0 does not validate and escape some of its slider options before outputting
The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the
A cross-site scripting (XSS) vulnerability in mccutchen httpbin v2.17.1 allows attackers to execute arbitrary web script
A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit th
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitra
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started