57,566 vulnerabilities published in 2026
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa
A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec
The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log en
GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause un
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications,
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could
A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D
The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo
The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the
The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authentica
Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows
Cross-repository issue/comment attachment re-linking can expose private attachment content
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker
A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could downloa
The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request a
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/
An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started