57,566 vulnerabilities published in 2026
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the requ
Gitea versions before 1.25.5 use release tag names and asset names as filesystem path components when dumping release as
A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of th
A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impacted is the function _deduplicate_results of the fil
A vulnerability was determined in AD-Security AD_Miner 1.9.0. Affected is the function request_a of the file ad_miner/sc
A vulnerability was determined in radareorg radare2 up to 6.1.6. This affects the function core_anal_bytes of the file l
Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrie
Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensit
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The ca
Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The came
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service v
pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource rea
Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN)
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range(
The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2
The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP
A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm
Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC func
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend
js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and lin
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed opt
U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFI
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/dir
pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared imag
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAu
Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper i
The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-proces
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session co
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe
The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attac
The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started