57,566 vulnerabilities published in 2026
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown fun
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unkno
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of
A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /A
A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affect
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server T
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server w
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue
A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Thi
A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46
A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function
A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cp
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes
NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office S
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile()
Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to
A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially craf
OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) mi
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl
KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrar
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi
ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vuln
A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nos
A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown functi
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/Pa
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read f
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunder
Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firef
In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to loca
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin). Supporte
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Leve
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK vers
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file lite
A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affecte
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorize
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started