57,566 vulnerabilities published in 2026
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update tic
A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete pos
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in th
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an una
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a ne
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Att
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute cod
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues:
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affe
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper p
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remot
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can resu
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output pa
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete op
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fail
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a cal
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started