57,566 vulnerabilities published in 2026
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead t
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow rem
Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party ori
Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via at
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packe
QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS s
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing en
Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged netwo
Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a use
On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibi
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co
Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decr
Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer derefere
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient
Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowE
Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Sup
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field dat
Vulnerability Title
Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-passwor
Administrator Cross Site Scripting (XSS) in WP Emmet <= 0.3.4 versions.
Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.
Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
subsys/net/ip/ipv6_mld.c:mld_send() read the packet interface via net_pkt_iface(pkt) after net_send_data(pkt) returned s
subsys/net/ip/icmpv6.c reads the network interface from a net_pkt after that packet has been handed to net_try_send_data
The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting t
Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control he
Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences
libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SS
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started