57,566 vulnerabilities published in 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the
Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar
Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory
Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code ins
Use after free in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to execute arbitrar
Race condition in Start in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker leveraging social
Improper state validation in Performance in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentiall
Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute
Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allow
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as r
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that
Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in
In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was st
@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) con
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before
The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all v
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. Thi
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLogin
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises th
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configu
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custo
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerabil
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evalu
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the automatic image-downlo
A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embed
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace ide
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. T
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2
Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve
In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: ensure accessible eth_hdr proto fi
In the Linux kernel, the following vulnerability has been resolved: rapidio/tsi721: prevent a bad dereference in tsi721
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowin
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoi
Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authentic
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:projec
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows a
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middl
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team membe
VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users t
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions b
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cros
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started