57,566 vulnerabilities published in 2026
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vu
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token
The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation
Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary g
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.l
FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network
The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insuff
Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware
Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial pac
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but t
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not ack
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was no
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the init
Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, w
Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14, which is affected by CVE
Nokogiri before 1.14.3 (CRuby implementation only, when using the packaged libxml2) bundles libxml2 v2.10.3, which is vu
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokeniz
The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prio
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Comp
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs o
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download
Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to poten
Improper enforcement of behavioral workflow in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker w
Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who h
Buffer overflow in Blink in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing t
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking w
Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token
GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated use
Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after passwo
Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allo
The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing
The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Par
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authen
mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSa
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Sof
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started