57,566 vulnerabilities published in 2026
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing
An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a c
An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin i
An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more tha
filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing at
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an u
Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (S
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne
The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6
Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request
A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using p
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affec
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affec
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Syne
sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injec
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (C
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended de
Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may a
The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the
The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gainin
An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, Fort
DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fe
The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl
The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the s
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a atored XSS issue in the OpenClaw Control UI when rend
Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{I
Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthentica
A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat De
A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defen
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated,
Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated,
Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which
Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started