57,566 vulnerabilities published in 2026
NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unau
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauth
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaus
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capab
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowi
The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns t
The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to buil
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_s
SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the N
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes l
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override exec
Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attac
The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and th
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrep
pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.val
Memos through 0.30.0 omits the 100.64.0.0/10 carrier-grade NAT address range from SSRF protection in its link-metadata f
### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a t
browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing atta
A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the compo
SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-vi
A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component N
A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_han
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /as
An erroneous authorization check in SAP Business Workflow leads to privilege escalation. An authenticated administrative
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitac
Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary Angula
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in it
Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi
EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorizat
EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful ex
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaSc
Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit
There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which
Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript exe
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the des
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started