57,566 vulnerabilities published in 2026
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection. This is
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Th
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerabili
Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local n
In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Softw
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Ar
Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n ru
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to u
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+
Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubp
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls A
A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the fi
Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software
The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registra
The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no
The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management opera
Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-qu
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SA
A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started