57,566 vulnerabilities published in 2026
Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabl
OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicti
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability a
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affec
Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to by
Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacke
OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials
Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote
Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking
Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application
OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channe
Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via t
ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM
Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can creat
CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera
Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stor
PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normall
Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit sema
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled
Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m
Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wo
Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users a
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o
The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file
An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible f
An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive all
An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which a
Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi
OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc
A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio
An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista E
Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an a
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to ve
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from vers
In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. T
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started