57,566 vulnerabilities published in 2026
Incorrect authorization in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to bypass
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to
Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever
UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to sp
Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web or
Incorrect authorization in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging so
Incorrect authorization in Input in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised t
Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially by
Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-orig
Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote atta
Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass sy
Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web orig
Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origi
Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass we
Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rend
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass
Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacke
Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data vi
Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging
UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had comprom
A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown
Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_pro
Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints
The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to th
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3
DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feat
Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instan
Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally s
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 doe
The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sal
The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Techno
Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a control
The updateWorkspace handler in mods/identity/src/workspaces/createUpdateWorkspace.ts in Fonoster through 0.22.7 invokes
RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values w
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email c
A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote au
When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused b
An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of
An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an
An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands
Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentica
An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to b
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started