57,566 vulnerabilities published in 2026
A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /soci
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi
A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic
A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function
A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown
A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component T
A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account
Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readab
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a us
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate t
MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain request
MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate reques
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerab
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer
Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its set
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final,
Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External De
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
The CMP WordPress plugin before 4.1.18 does not sanitise and escape a settings value before outputting it on the coming
openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, wh
A vulnerability was determined in cyberchitta scrapling-fetch-mcp up to 0.2.2. The impacted element is the function s_fe
A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src
A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown functi
A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component Us
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phi
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs u
Due to a CRLF Injection vulnerability in SAP NetWeaver Application Server Java, an authenticated attacker with administr
Dell PowerScale OneFS, versions 9.10.0.0 through 9.13.1.0, contains an external control of system or configuration setti
Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON
Pega Platform versions 8.1.0 through 25.1.0 are affected by a Stored Cross-site Scripting vulnerability in a user interf
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic
The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting
In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.
draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts
SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing h
A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnera
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started