2026
57,566 vulnerabilities published in 2026
Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Deni
A Improper Authentication vulnerability in TLP allows local users to arbitrarily control the power profile in use as wel
Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to rev
In Crazy Bubble Tea mobile application authenticated attacker can obtain personal information about other users by enume
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Use spinlock for context l
TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted out
A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to exe
Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3 versions 3.0.0 and later allows authenti
Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to
Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_up
Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU
Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models all
Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload
GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extend
Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site
Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and pr
The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-
Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are
Reflected Cross-Site Scripting (XSS) vulnerability in Riftzilla's QRGen. This vulnerability allows an attavker to execut
HTML Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation
Reflected Cross-Site Scripting (XSS) vulnerability in IsMyGym by Zuinq Studio. This vulnerability allows an attacker to
HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an
A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open
Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various
A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secre
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not b
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigat
The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigati
When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messa
User-controlled header names and values containing newlines can allow injecting HTTP headers.
Authentication Bypass by Primary Weakness vulnerability in Jamf Jamf Pro allows unspecified impact.This issue affects Ja
ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in
ManageIQ is an open-source management platform. A flaw was found in the ManageIQ API prior to version radjabov-2 where a
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java ap
Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows.
Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by
MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permis
EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and e
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and e
VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a local p
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and e
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally con
A low-privileged user can bypass account credentials without confirming the user's current authentication state, which m
An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when seria
Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae4
Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of m
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started