57,566 vulnerabilities published in 2026
Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 f
Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r
Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compro
Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re
Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker
Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende
Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf
Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineerin
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re
Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf
Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive in
Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A m
The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (rel
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before r
The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through i
The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored s
The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restr
The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only f
The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed t
The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJA
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal s
CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remot
The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc
Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller
In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerabi
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is
The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor N
A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the
A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_conte
The Document Embedder WordPress plugin before 2.3.1 does not check a document's status before issuing a download token
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown
The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in a
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of t
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the fi
Observable discrepancy vulnerability in Seres Software syWEB allows Account Footprinting. This issue affects syWEB: thr
APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. Reso
The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each admi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started