57,566 vulnerabilities published in 2026
A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process
A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of
SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fi
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0,
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.se
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to th
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX
Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of th
Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authent
A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown
A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_c
A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function amf_namf_comm_decode_ue_m
A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/na
A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_
A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of t
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a mani
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language M
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vuln
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user
Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th
Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). Th
EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated
A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of inte
The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. W
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Priv
A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. Th
A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function P
An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS
Race condition in the JavaScript: GC component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
Local admin could to leak information from the Genetec Update Service configuration web page. An authenticated, admin pr
A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_ON_OAUTH_CALLBACK` e
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurre
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race (C++ UB) triggered by an A 1-phas
Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client allows Privilege Escalation.
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started