57,566 vulnerabilities published in 2026
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placi
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Publi
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or at
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authentic
In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, w
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib
BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and ant
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg rev
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a danger
Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sens
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constru
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under diff
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that m
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all
It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) cond
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a C
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin
X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLR
Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informa
Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an
Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive infor
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Con
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthe
In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a
In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for examp
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its bac
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication m
FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals())
ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without strippin
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started