57,566 vulnerabilities published in 2026
A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsm_handle_pdu_session_modification_qos
A vulnerability was identified in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_update_da
A security flaw has been discovered in Open5GS up to 2.7.7. This issue affects the function smf_nsmf_handle_update_data_
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without
A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the fi
A security vulnerability has been detected in Open5GS up to 2.7.7. The affected element is the function yuarel_parse in
Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis
OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to
@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/col
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpo
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, mac
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS T
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and
WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler
A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Mes
Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticat
Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users
SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions tem
The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorizatio
The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to a
The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in
The Woo Commerce Minimum Weight plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a
The Forms Rb plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9. Thi
The WP-Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including
The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user
An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple
Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no add
An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDec
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose
Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyG
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacke
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r
The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat
The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in al
Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts
An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can oc
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started