57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: update last_gc only when G
In the Linux kernel, the following vulnerability has been resolved: nvmet: fix race in nvmet_bio_done() leading to NULL
In the Linux kernel, the following vulnerability has been resolved: smb/server: fix refcount leak in parse_durable_hand
Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_
An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as r
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Na
The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based
The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification
The WPNakama – Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerable
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate sp before freeing associate
Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 all
When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate. Note: Software versions
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allo
Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vul
ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by in
XMedia Recode 3.4.8.6 contains a denial of service vulnerability that allows attackers to crash the application by loadi
Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system
Foscam Video Management System 1.1.4.9 contains a denial of service vulnerability in the username input field that allow
iSmartViewPro 1.3.34 contains a denial of service vulnerability that allows attackers to crash the application by overfl
gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by m
FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by ma
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to crash the a
Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin
MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module.
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch
The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version
OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when
Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constra
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage`
The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version
strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the datab
Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via t
The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v
emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are access
Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c
soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` ma
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an atta
NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOf
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to vers
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulne
go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through
OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept w
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows
OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx
OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendM
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started