57,566 vulnerabilities published in 2026
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash
NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper lim
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a rest
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful e
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause serv
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMA
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscri
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/u
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast di
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discover
open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemo
open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via direc
VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of t
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported m
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress au
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX action
The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing un
The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an u
The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST
The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled sett
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter
When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz
** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af
In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_ech
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started