57,566 vulnerabilities published in 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trus
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"
In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to a
In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the
In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role cou
In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authentica
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorizati
Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the
A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection,
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromise
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper au
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information and cause a
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-bas
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final na
Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow
llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows u
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 un
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which auth
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token
In the Linux kernel, the following vulnerability has been resolved: ima: Instantiate file_truncate and path_truncate ho
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie(
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP hea
D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers wi
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that al
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop actio
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated u
The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes
The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. T
The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This ma
hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML esc
The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper cer
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause w
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started