57,566 vulnerabilities published in 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jagdish1o1 Delay R
A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary
A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t
A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min
Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un
Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 a
vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry
Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made b
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Althou
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP respon
Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inc
Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isC
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) s
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with con
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc
Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerabi
A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a car
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data i
IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniqu
IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nabil Lemsieh Hurr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolut
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGall
Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulne
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Galler
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silence Silencesof
Missing Authorization vulnerability in vertim Schedula schedula-smart-appointment-booking allows Exploiting Incorrectly
Insertion of Sensitive Information Into Sent Data vulnerability in themeglow JobBoard Job listing job-board-light allows
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. F
Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but d
An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s
Astro is a web framework. In versions 9.0.0 through 9.5.3, Astro server actions have no default request body size limit,
ImageMagick is free and open-source software used for editing and manipulating digital images. The shipped "secure" secu
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started