57,566 vulnerabilities published in 2026
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted fr
Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitra
Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to perform an out o
Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker wh
Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of boun
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bound
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrar
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to
Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malic
Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbit
Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker t
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-ma
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST
MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable
Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via
Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had
Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compr
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin
The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and in
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privile
Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted s
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams fo
Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a net
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code ov
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthoriz
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy()
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with tr
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modif
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs du
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (app
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any pac
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authen
An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a
A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, Es
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, om
FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function
Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handli
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started