57,566 vulnerabilities published in 2026
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 -
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers t
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows a
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt f
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKe
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell c
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two b
In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the r
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to exe
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enou
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG reco
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runawa
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the z
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for on
FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtp
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) ha
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorith
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extension
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third
@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its
The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths c
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
Contributor Local File Inclusion in Vino <= 1.9 versions.
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ver
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the
When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid
Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started