57,566 vulnerabilities published in 2026
Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitr
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp
Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to impro
The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and in
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly s
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a bina
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_l
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signatur
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over
Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a net
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operati
LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The
The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into Tok
An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attack
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers
The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus
Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values dir
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrar
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.1
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior t
Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, P
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privile
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenti
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malici
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exi
OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows au
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redir
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authe
OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with
OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env
Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrar
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started