57,566 vulnerabilities published in 2026
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation e
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/inval
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensit
Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core
kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in o
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS a
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens witho
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable
Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain nul
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Valida
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.E
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows at
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix Route Information option length validatio
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix sk_buff leak when the header
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: defer invalid log until af
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: release template ct on non-IP pa
In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_netdev: Preserve RX queue depth on allocat
In the Linux kernel, the following vulnerability has been resolved: net: usb: ax88179_178a: fix skb leak in ax88179_tx_
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix TOCTOU race between smc_listen_out() a
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_flow_table: drop existing skb dst bef
In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport m
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fw_tracer, return NULL on create error T
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but no
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkificatio
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During Ju
exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, tot
exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remot
fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parse
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never
Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS,
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validati
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta
HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or
Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from
Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cg
An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-
A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS throu
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh pa
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Tel
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started