57,566 vulnerabilities published in 2026
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improp
NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper r
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinE
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locall
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_da
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shar
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS)
GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak he
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to u
In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix board ID over-read The EEPROM board
In the Linux kernel, the following vulnerability has been resolved: net: tap: set skb->dev before parsing virtio net he
In the Linux kernel, the following vulnerability has been resolved: net/atm: fix slab-out-of-bounds read in vcc_setsock
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Validate T10 PI scatterlist counts Whe
In the Linux kernel, the following vulnerability has been resolved: vhost_iotlb: bound map allocation in add_range vho
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers t
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued conn
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site accou
An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized u
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webh
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() ra
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear
Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI wit
In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `de
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started