57,566 vulnerabilities published in 2026
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the pack
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certifi
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routin
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev
CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclo
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Lev
A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevi
A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestin
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model co
Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY
PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend w
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource
Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c
Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConf
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretraine
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior
The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/sr
o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers
9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate use
An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in
A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establi
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to
The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Inject
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depe
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAP
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...
HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_p
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7,
zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores at
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the a
CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when
WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 93
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started