57,566 vulnerabilities published in 2026
The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX action
Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow a
js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithm
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted c
protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unkno
opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetr
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, t
@astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function
Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778
Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture
Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigne
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section re
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated
dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_mak
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi
The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7.
The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, a
The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions
The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modifi
The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorizati
The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure i
Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allo
Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verifi
Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the rend
Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potenti
Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members sign
Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo
Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, an
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of bei
An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have
This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative
An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured wit
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Docum
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPath
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started