57,566 vulnerabilities published in 2026
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 t
NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound
A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3
An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cau
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a use
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in
The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the
An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The ser
In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max
The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 vi
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp
Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The en
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the lu
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Net
A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulne
A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (COR
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodli
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper A
A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in U
A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulne
Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitr
The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientH
Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 hand
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s
Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated
Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed docume
Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document
pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The pars
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s
An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation wou
A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create
The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4
The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service agai
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe
In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servic
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transf
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the document
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started