57,566 vulnerabilities published in 2026
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who ha
Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfre
pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_
Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to re
A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::exec
dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handl
In the Linux kernel, the following vulnerability has been resolved: ice: fix race condition in TX timestamp ring cleanu
In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix unmap race with PMD migration entr
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had com
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the fi
GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util
A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin
Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unau
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 1
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a re
In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a
The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that,
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request
ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview dep
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar
The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N
A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/
A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryControl
A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of
A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown functi
Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeave
A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p
secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th
A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of t
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings o
Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started