57,566 vulnerabilities published in 2026
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthen
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local at
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed a
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials
Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i
Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API
Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing d
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-
bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the
The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in
In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists
In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one p
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set befo
Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient ro
Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) ma
Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() wo
Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks,
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix oops due to out of scope access Be
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: join hook list via splice_lis
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate bg_bits during freefrag scan [BUG]
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix listxattr handling when the buffer is fu
In the Linux kernel, the following vulnerability has been resolved: soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric
In the Linux kernel, the following vulnerability has been resolved: drm/komeda: fix integer overflow in AFBC framebuffe
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix OOB in pcpu_init_value An out-of-bounds r
Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/read
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue vi
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Bound VBIOS record-chain walk loop
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix buffer over-read in rtw_upd
In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate cpu_id against nr_cpu_ids in DM
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add buffer overflow check in MS get_inf
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds checks for firmware log indi
In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: reject short frames before parsing
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate advertising TLV before ty
In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limi
In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write a
In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock
Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started