57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: fix race condition in qman_destroy
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Synchronize interrupts before susp
util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vuln
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
A flaw has been found in SourceCodester/jkev Record Management System 1.0. Affected by this issue is some unknown functi
Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a
The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phis
A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the fil
A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the
A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /
A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getCon
A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFree
In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the sess
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availabi
A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServe
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_a
DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style
A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file applicat
A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/Ap
A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/mod
Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stor
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup
In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk: fix race between concurrent split and
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix folio isn't locked in softleaf_
In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A us
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device m
The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are init
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass
CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS
In the Linux kernel, the following vulnerability has been resolved: smb: client: make use of smbdirect_socket.recv_io.c
In the Linux kernel, the following vulnerability has been resolved: i2c: designware: amdisp: Fix resume-probe race cond
In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a
Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the Ci
A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of th
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of th
A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of t
A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function q
A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of t
A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of th
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file'
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PH
A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function dele
A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started