57,566 vulnerabilities published in 2026
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerabilit
A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps
A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_e
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated att
Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their perm
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Split
A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown pr
Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Se
A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section
A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the fil
Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Acce
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access C
Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Acces
Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control
Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Config
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code
A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa
A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component
A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqob
IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default pas
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectl
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allow
Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values w
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to den
The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec
Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro
IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote at
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the Prod
A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code o
A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown processing of the compo
FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information discl
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, an
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially cra
A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vuln
The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19.
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Mis
PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u
opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing tel
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restricti
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() stri
Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass c
Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclos
Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started