57,566 vulnerabilities published in 2026
Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applica
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnera
RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frame
An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the paren
An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capt
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to
A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write pat
Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
The affected Ebyte device web management interface does not restrict the interface from being rendered within an extern
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when pro
xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript v
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Sof
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attac
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to per
Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission check
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() i
The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its setti
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT acces
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?ac
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username e
The Comments WordPress plugin before 7.6.40 does not properly validate user's identity when using the disqus.com provid
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure
A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::Inse
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decom
A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m
A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/conn
The Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission – WP User
The Ninja Forms WordPress plugin before 3.13.3 allows unauthenticated attackers to generate valid access tokens via the
A vulnerability has been found in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3. This vulnerability af
REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.
CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retr
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an information disclosure vulnerability that allows un
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows
An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to u
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started