57,566 vulnerabilities published in 2026
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a ma
An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand)
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper N
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packe
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the
GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is
vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions
vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon
The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamica
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File Syst
A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tra
A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory con
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.
FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can
CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters usi
CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy
An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientH
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middle
sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransp
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Tran
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat
Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalI
The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively re
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u49
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framewo
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Java Business Objects). Supporte
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started