57,566 vulnerabilities published in 2026
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can
Collabora Online is a collaborative online office suite based on LibreOffice technology. Prior to Collabora Online Devel
A vulnerability was found in Edimax BR-6208AC 2_1.02. The affected element is the function auth_check_userpass2. Perform
A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the
A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/
A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pf
A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component
A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component
The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to unauthorized access in all versions
A security vulnerability has been detected in happyfish100 libfastcommon up to 1.0.84. Affected by this vulnerability is
A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of
A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown funct
A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an u
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox Centr
A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/
PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeratio
Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint widget.app.ping accepts an
Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2,
Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user
The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and inclu
A vulnerability was determined in jsbroks COCO Annotator up to 0.11.1. This impacts an unknown function of the file /api
A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/public
A weakness has been identified in Tenda AC21 16.03.08.16. This impacts an unknown function of the file /cgi-bin/Download
A security vulnerability has been detected in Tenda AC21 16.03.08.16. Affected is an unknown function of the file /cgi-b
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The library version could be
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Since there are input fields
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed
Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7.
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Uni
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
Crafted zones can lead to increased incoming network traffic.
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security v
FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessi
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these op
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Obj
A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file strea
Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before vers
Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Author
Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled,
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, poten
JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the
The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to,
The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access
An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/us
An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started