57,566 vulnerabilities published in 2026
An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi
An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive applicati
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of
An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi
Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, P
The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of th
The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,
The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/
In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation error b
In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream sta
In the Linux kernel, the following vulnerability has been resolved: xfrm: ipcomp: Free destination pages on acomp error
Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginm
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carr
An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue aff
In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" T
In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync s
In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_ch
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ce
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential null-ptr-deref in decode_cho
In the Linux kernel, the following vulnerability has been resolved: ceph: put folios not suitable for writeback The ba
In the Linux kernel, the following vulnerability has been resolved: net: tls: fix strparser anchor skb leak on offload
In the Linux kernel, the following vulnerability has been resolved: neigh: let neigh_xmit take skb ownership neigh_xmi
In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix BQL imbalance in TX path Fix a po
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix potential NULL derefe
In the Linux kernel, the following vulnerability has been resolved: pppoe: drop PFC frames RFC 2516 Section 7 states t
In the Linux kernel, the following vulnerability has been resolved: NFSD: fix nfs4_file access extra count in nfsd4_add
In the Linux kernel, the following vulnerability has been resolved: net, bpf: fix null-ptr-deref in xdp_master_redirect
In the Linux kernel, the following vulnerability has been resolved: sctp: disable BH before calling udp_tunnel_xmit_skb
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix leaking free_bds While reclaimi
Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 unti
concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a p
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustio
Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user t
@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulne
The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication contr
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS c
Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file
Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Se
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Trave
ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability
A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box
A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' para
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started