57,566 vulnerabilities published in 2026
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer pa
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit prop
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does n
SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implemen
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that return
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugi
openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call i
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configur
Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Pro
Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Prope
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.
INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack bu
Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() func
COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attacker
COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthentic
Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2,
Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensi
TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that al
An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request he
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unaut
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issu
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthe
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows un
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths t
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer I
SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (incl
SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints tha
ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforce
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 11
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, T
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird
Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 1
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPending
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAt
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started