57,566 vulnerabilities published in 2026
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows una
Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote att
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu
Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can
The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a
Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica
facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u
facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau
facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access control
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.
In the Linux kernel, the following vulnerability has been resolved: net, bpf: check master for NULL in xdp_master_redir
SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlqu
An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the fil
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauth
An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI fu
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path va
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory D
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via t
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec
The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.
The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to
Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To m
Addressing certain issues, in particular related to operations which may take excessively long and therefore would need
Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest ch
The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that
Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthe
GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.
Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limite
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow dec
gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes
Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass acce
TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available me
TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to
TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary fi
pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscrib
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started