57,566 vulnerabilities published in 2026
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-al
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that al
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remot
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex paramet
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x *
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends
Private Repository Existence Disclosure via go-get Meta Endpoint
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request t
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DR
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitializ
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when pro
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bo
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST
A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadR
A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin
A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of th
Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of
A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method p
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vul
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_m
An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effec
js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due t
A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Uni
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` par
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versi
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind S
The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor docu
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db
The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 vi
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D
A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted eleme
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership che
A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknow
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwis
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py c
A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started