57,566 vulnerabilities published in 2026
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` d
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file hand
OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to termi
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's serv
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthe
Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenti
The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transact
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of inco
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attem
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist f
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engag
Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to instal
Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a us
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engag
Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to instal
Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the render
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer lengt
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0,
Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially craf
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating
By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count
In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started