57,566 vulnerabilities published in 2026
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks m
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenti
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious br
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a ma
TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3
libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote pee
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal as
OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the
Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecke
libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions
Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabl
Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and serv
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to v
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, a
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypass
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapte
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt
Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and befor
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype N
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unaut
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache
Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior t
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built
form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argumen
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started