57,566 vulnerabilities published in 2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyl
H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability i
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacke
OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes,
WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialM
Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsi
Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full reque
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.
NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registr
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18
fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte ou
IBM Concert 1.0.0 through 2.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry
IBM Concert 1.0.0 through 2.2.0 transmits data in clear text that could allow an attacker to obtain sensitive informatio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/
Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when un
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent
A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col
Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP resp
Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap
Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, ther
An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQ
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Ru
A non-default configuration in Sage DPW 2025_06_004 allows unauthenticated access to diagnostic endpoints within the Dat
IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker t
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path
The leancrypto library is a cryptographic library that exclusively contains only PQC-resistant cryptographic algorithms.
vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before version 0.18.0, L
LTI JupyterHub Authenticator is a JupyterHub authenticator for LTI. Prior to version 1.6.3, the LTI 1.1 validator stores
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed l
An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolve
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Boo
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTa
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qub
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani WP Si
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Kor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chief Gnome Garden
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fesomia FSM Custom
Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modif
Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started