57,566 vulnerabilities published in 2026
The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li
Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVu
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerabil
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elix
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic
SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows una
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi
Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Network
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo
Uncontrolled Resource Consumption, Deserialization of Untrusted Data vulnerability in hexpm hex_core (hex_api modules),
phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/p
Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 e
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Win
The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon
Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Mani
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of
The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks.
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensiti
An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain v
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verificatio
Always-Incorrect Control Flow Implementation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENE
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherN
Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET/IP Et
An issue was discovered in 6.0 before 6.0.3, 5.2 before 5.2.12, and 4.2 before 4.2.29. `URLField.to_python()` in Django
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, and 2400. A NULL pointer dereference
An issue was discovered in LBS in Samsung Mobile Processor Exynos 2200. There was no check for memory initialization wit
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. A NULL pointer
Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to use a weak cryptography algorithm for da
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can caus
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started