57,566 vulnerabilities published in 2026
Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to per
Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially expl
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exp
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) v
Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3,
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can up
A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents t
Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios
The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project eva
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorizatio
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to req
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote
A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the
Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between appro
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authentic
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows
We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path t
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the f
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknow
A vulnerability was determined in GALAYOU Y4 1.0.0. Impacted is an unknown function of the component Web Server. This ma
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Ex
Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affe
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) pr
Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sens
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorr
Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.
Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
Customer Privilege Escalation in Dokan <= 5.0.2 versions.
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate
Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or mo
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABT
The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in version
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpf
Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exp
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.
Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started