57,566 vulnerabilities published in 2026
gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-con
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable
The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero leng
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat
The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent
The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowin
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connecto
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the a
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded thr
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log informatio
Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus
Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets v
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to v
A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker t
A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and down
An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept
A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras
A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que
In the Linux kernel, the following vulnerability has been resolved: audit: fix recursive locking deadlock in audit_dupe
In the Linux kernel, the following vulnerability has been resolved: tcp: initialize standalone TCP-AO response padding
In the Linux kernel, the following vulnerability has been resolved: rtase: Workaround for TX hang caused by hardware pa
In the Linux kernel, the following vulnerability has been resolved: gve: fix Rx queue stall on alloc failure When the
In the Linux kernel, the following vulnerability has been resolved: rbd: Reset positive result codes to zero in object
In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in afiucv_hs_callback_s
In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors
In the Linux kernel, the following vulnerability has been resolved: libceph: guard missing CRUSH type name lookup Loca
In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attr
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Ge
In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strrese
In the Linux kernel, the following vulnerability has been resolved: tcp: fix TIME_WAIT socket reference leak on PSP pol
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel sched scan results work on u
A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticate
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at
A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote att
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Sta
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith
The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) pars
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started