57,566 vulnerabilities published in 2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled.
Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnera
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A s
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an aut
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation
A party with write access to stored session data may affect JFrog Artifactory under specific conditions.
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to ex
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_
Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnera
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and
A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1,
Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Sup
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Follow
In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR co
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before
Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to acces
EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3,
Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffm
The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to
A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of th
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.
Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion i
There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered
There is an integer overflow vulnerability resulting in an out-of-bounds write recently discovered in NI LabVIEW. This
The Defender Security WordPress plugin before 6.2.0 does not restrict a network-wide setting to network administrators,
A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — fu
Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks m
aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the hand
The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when impor
Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX
The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthentica
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
An allocation of resources without limits or throttling vulnerability has been reported to affect several QNAP operating
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
An out-of-bounds read vulnerability has been reported to affect License Center. If a remote attacker gains a user accoun
A buffer overflow vulnerability has been reported to affect License Center. If a remote attacker gains an administrator
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started