57,566 vulnerabilities published in 2026
Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#in
The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by p
Substance3D - Designer is affected by a NULL Pointer Dereference vulnerability that could result in an application denia
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Illustrator is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An att
Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memo
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu
NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive inf
Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a local attacker to obtain sensitiv
Information leak in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain
GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 19.1.7, 19.2 before 19.2.5, and 19.3
A flaw was found in the Seattle FilmWorks plugin in GIMP. When processing a specially crafted SFW image file, the plugin
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter
openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specifi
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution fla
openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file m
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory ex
DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to applicat
A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function
A security vulnerability has been detected in RooCodeInc Roo-Code up to 3.51.1. This affects the function fetch_instruct
A vulnerability was found in MAA-AI MaaMCP up to 1.1.1.dev6+g2e4a41287. The affected element is the function save_pipeli
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote
A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper t
browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or
Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability in the `
Emlog is an open source website building system. Version 2.5.23 has a stored cross-site scripting vulnerability that can
listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to version 6.0.0, lower-privileged use
A vulnerability was determined in cld378632668 JavaMall up to 994f1e2b019378ec9444cdf3fce2d5b5f72d28f0. Affected is the
Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to
Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issu
An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP co
The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to unauthoriz
Missing Authorization vulnerability in BuddhaThemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-ad
Missing Authorization vulnerability in Fahad Mahmood RSS Feed Widget rss-feed-widget allows Exploiting Incorrectly Confi
Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly C
An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server
The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and dis
The LearnPress – WordPress LMS Plugin for WordPress is vulnerable to unauthorized file deletion in versions up to, and i
Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbru
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
The Report Builder component of the application stores user input directly in a web page and displays it to other users,
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started