57,566 vulnerabilities published in 2026
pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity de
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This
The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin
The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content m
The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and inc
A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by
A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec o
A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea.
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/R
Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing c
Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication,
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (c
Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerabi
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu
SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue
SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet
SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue
A security vulnerability has been detected in lm-sys fastchat up to 0.2.36. This issue affects the function api_generate
A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena S
Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context han
Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa
A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function
OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingre
OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that a
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Em
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10,
Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, al
XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) h
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root execut
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l
free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generati
Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusRea
Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large
The CalJ plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5. This is
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started