57,566 vulnerabilities published in 2026
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.4.0 through 5.1
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Versions 5.10 through 5.11
AutoMapper is a convention-based object-object mapper in .NET. Versions prior to 15.1.1 and 16.1.1 are vulnerable to a D
free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerabi
free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerabili
SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Se
Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS appl
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-be
libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, th
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions prior to 1.4.2
Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading
H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream i
Bitcoin Core 0.13.0 through 29.x has an integer overflow.
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow expli
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side T
DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL u
A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated r
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una
SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can per
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated f
WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthe
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, al
OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering
OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system
The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedF
The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,
The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, a
CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submi
Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by pro
phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbit
EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials
Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by
WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vuln
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsb
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to hand
An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s a
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` en
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started