57,566 vulnerabilities published in 2026
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spo
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network
A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject s
An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors runnin
Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service thr
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-1
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana Fleet can lead to Excessive Allocation (CAPEC-1
Improper Input Validation (CWE-20) in Kibana's Email Connector can allow an attacker to cause an Excessive Allocation (C
VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate d
Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to re
AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes appl
The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ
Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Over
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls comman
Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notifi
A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads wh
An SQL injection vulnerability in InvoicePlane through 1.6.3 has been identified in "maxQuantity" and "minQuantity" para
Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settin
A heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS
An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an
A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) Juniper Networks
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N
An Incorrect Calculation vulnerability in the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS E
A Use After Free vulnerability in the chassis daemon (chassisd) of Juniper Networks Junos OS and Junos OS Evolved allows
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. LakeFS's S3 gateway does not
The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis
The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deleti
Path Traversal vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If this vu
In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some
PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with acc
The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi
The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to ar
A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records t
OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and
Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to
HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ce
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version
SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file
MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypas
Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An au
ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage me
The Bookingor WordPress plugin through 1.0.12 exposes authenticated AJAX actions without capability or nonce checks, al
Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in t
A code injection vulnerability in the binary-parser library prior to version 2.3.0 allows arbitrary JavaScript code exec
Open 5GS WebUI uses a hard-coded JWT signing key (change-me) whenever the environment variable JWT_SECRET_KEY is unset
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-dele
Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Pl
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started