57,566 vulnerabilities published in 2026
xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W
Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo
A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information d
Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt
Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se
Local File Inclusion via file:// URI in Migration Restore
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper
A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls
The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi
The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripti
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 u
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrol
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and be
A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn o
The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in version
A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validate
CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w
The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is suppl
A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft E
SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/mo
A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results
The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin f
Plane is an an open-source project management tool. In plane.io, a guest user doesn't have a permission to access https[
Emlog is an open source website building system. In version 2.5.23, the admin can set controls which makes users unable
A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat
Missing Authorization vulnerability in WPvibes AnyWhere Elementor Pro allows Exploiting Incorrectly Configured Access Co
A vulnerability was detected in code-projects Online Product Reservation System 1.0. The affected element is an unknown
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress Thim Core allows Cross Site Request Forgery.This issue affe
PLANKA 2.0.0 lacks X-Frame-Options and CSP frame-ancestors headers, allowing the application to be embedded within malic
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting
The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on th
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to unauthorized m
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started