57,566 vulnerabilities published in 2026
The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' setti
The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_c
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistenc
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences.
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's rea
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version
A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attac
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to befo
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path
AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without
CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers
An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link f
The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings
The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via
PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M
Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor befor
Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass
Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 148.0.7778.96 allowed a local
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-langu
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of
The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,
The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up
An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local a
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature l
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write e
The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up
When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a high
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recur
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is v
The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.
The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona S
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored valu
NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an i
nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token intr
The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (D
IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could all
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently
The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started