57,566 vulnerabilities published in 2026
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Sec
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).
The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 2
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service
Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe
A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is
In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive con
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data a
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensiti
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec
The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to in
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk s
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to sto
The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrupts. On the PL011, th
Grav plugin-api before 1.0.15 contains a script injection vulnerability where the SVG sanitizer only checks for the exac
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cro
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate cer
MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate reque
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Genera
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2,
broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are c
Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Ver
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints i
openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB
Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the r
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started