57,566 vulnerabilities published in 2026
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate
Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path o
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and
Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5,
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue af
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2
A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corru
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthen
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cl
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr
Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asser
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the
In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-ver
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ Duri
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ss
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious S
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that a
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio
In the Linux kernel, the following vulnerability has been resolved: svcrdma: wake sq waiters when the transport closes
In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - restore callback for non-parallel
In the Linux kernel, the following vulnerability has been resolved: sched/rt: Have RT_PUSH_IPI be default off for non P
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require source read access for duplicate ext
In the Linux kernel, the following vulnerability has been resolved: netfilter: handle unreadable frags sashiko reports
In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid calling pci_irq_vector() from hardi
datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who contr
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This i
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects A
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects A
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This iss
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This i
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects A
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started