57,566 vulnerabilities published in 2026
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remo
Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree opera
Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages
Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdem
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attac
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject mapping a reserved doorbell to a
In the Linux kernel, the following vulnerability has been resolved: arm64: make huge_ptep_get handled unaligned address
In the Linux kernel, the following vulnerability has been resolved: ublk: wait on ublk_dev_ready() instead of ub->compl
In the Linux kernel, the following vulnerability has been resolved: media: cedrus: skip invalid H.264 reference list en
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check bounds on CRIU restore queue type
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix user array stride in pvr_set_u
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix MCIA register buffer overflow on 32 d
In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2781: bound firmware description string pa
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking
In the Linux kernel, the following vulnerability has been resolved: xfrm: reject optional IPTFS templates in outbound p
In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reasse
An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i
Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l
Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta
An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff wit
The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT perm
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getShee
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JS
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory
An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started