57,566 vulnerabilities published in 2026
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before stor
Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated rem
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authe
Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r
Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da
Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider an
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, a
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host he
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unau
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, ma
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:s
CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercep
Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the re
Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker
Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromise
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi
The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack
OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/m
Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default alg
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a
Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predict
The Naxclow platform exposes a registration endpoint that accepts signed requests containing a batch prefix and an arbit
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to be
A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component
A vulnerability has been found in Genspark AI Workspace App 2.8.4 on Android. This vulnerability affects unknown code of
A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality
A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown par
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of th
A security vulnerability has been detected in RubyLouvre avalon up to 2.2.10. The impacted element is an unknown functio
A weakness has been identified in svaarala duktape up to 2.99.99. This issue affects some unknown processing of the file
The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax f
The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marke
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform un
Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using d
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started