57,566 vulnerabilities published in 2026
Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr
An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proxi
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoin
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overfl
In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. T
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the lo
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting i
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL w
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripti
Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow an
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before
OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide com
A vulnerability was detected in Yealink SIP-T46U 108.87.50.1. The affected element is the function StartReportInformatio
A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload
A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/u
A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. T
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The sup
Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versi
In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. T
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell t
Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp c
py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: hold listener socket in rfcomm_c
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-po
The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowe
Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forgin
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started