57,566 vulnerabilities published in 2026
Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malic
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to i
Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the oper
A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU proce
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attack
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ran
Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substi
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sen
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive infor
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to r
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remo
When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components
OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environm
Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T
Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to ver
Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filt
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a
IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1
IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c
SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf
SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool J
Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a s
An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to r
The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A mis
An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mc
Full details and mitigation steps are currently restricted and will be published at a later date.
Full details and mitigation steps are currently restricted and will be published at a later date.
Full details and mitigation steps are currently restricted and will be published at a later date.
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ
ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started