57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: reject invalid CCM interval at configu
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in accept_untracked_na(
In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - fix OOB read in pefile_di
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bpa10x: avoid OOB read of revision strin
In the Linux kernel, the following vulnerability has been resolved: net: psample: fix info leak in PSAMPLE_ATTR_DATA p
A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the
Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with li
The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` me
Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote
The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of
Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a s
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding
Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated at
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fai
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form proce
Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitra
Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tec
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with acces
Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An atta
Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before in
Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions
Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affec
Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpol
Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-
Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG i
Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering
MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-t
`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index pred
sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite func
sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite agg
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, intern
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern
A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated a
Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18
SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries
diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application
CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d
CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut
CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize
A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in
A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se
Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started