57,566 vulnerabilities published in 2026
python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-S
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the
A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file
A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admi
A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the fun
NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem
A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, re
ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could e
A security flaw has been discovered in Edimax BR-6675nD 1.12. Impacted is the function mp of the file /goform/mp of the
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function dele
A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown
A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the fil
NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition b
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the
A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The
In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: Fix race condition when checking rpm
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix ip_rt_bug race in icmp_route_lookup rever
In the Linux kernel, the following vulnerability has been resolved: bpf: Require frozen map for calculating map hash C
In the Linux kernel, the following vulnerability has been resolved: hwrng: core - use RCU and work_struct to fix race c
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix damos_walk() vs kdamond_fn() exi
In the Linux kernel, the following vulnerability has been resolved: mm: fix deferred split queue races during migration
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix damon_call() vs kdamond_fn() exi
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing.
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix btrfs_ioctl_space_info() slot_count TOCT
In the Linux kernel, the following vulnerability has been resolved: wifi: rsi: fix kthread lifetime race between self-e
typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind
A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of
A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function ac
A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Adminis
A vulnerability was found in SourceCodester Water Billing Management System 1.0. Impacted is an unknown function of the
A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the f
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the functi
In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysf
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versi
Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who ha
Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rend
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the fi
A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function insertPlatformConfig of the file jshERP-b
In the Linux kernel, the following vulnerability has been resolved: pseries/papr-hvpipe: Fix race with interrupt handle
SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai
A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an au
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati
A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of t
Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started