57,566 vulnerabilities published in 2026
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetim
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `repla
Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of
When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is pa
On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `mu
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that le
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base syst
EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2
OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitra
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separ
goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in
Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax
Ruckus Unleashed contains a remote code execution vulnerability in the web-based management interface that allows authen
The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format cod
The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can s
Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU u
Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affect
The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-boun
Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, p
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expr
A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-
Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulner
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attack
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att
Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. Whe
In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value fo
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical confi
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra
A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251
Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and b
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to pass
Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoint
Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extens
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Fina
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Fina
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started