57,566 vulnerabilities published in 2026
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce meth
picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbi
picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle redu
picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle
picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to b
picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basich
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, all
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to byp
picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for mal
Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 bu
Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The
The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before
Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP respo
Deserialization of Untrusted Data vulnerability in Apache Camel. The default ObjectInputFilter pattern shipped with sev
Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component crea
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri
Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g
Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to
Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without
Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data be
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure
Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized ac
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remot
When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disab
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors r
Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and mak
An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attac
An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and rep
A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to exec
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all version
The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions
The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid appl
FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot en
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for ur
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Ma
TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHtt
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance f
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphin
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started