57,566 vulnerabilities published in 2026
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/hel
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst
Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media
ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's external identity provider handler ch
Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, default.blade.php renders header_color and related br
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_manag
Incorrect Authorization vulnerability in Drupal AI Agents allows Forceful Browsing. This issue affects AI Agents version
Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue a
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Salesforce Suite allows Cross Site Request Forgery. This issue
Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field na
The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Serv
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configu
Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availab
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a u
Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/pa
NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review
HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise
A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34).
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t
Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants). The supported
Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). Th
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSI
Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values coul
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML
A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled s
Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the n
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so
Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh
undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before
undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Ta
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren
The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using
OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al
Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al
The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outp
The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started