57,566 vulnerabilities published in 2026
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unkno
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of
A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /A
A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affect
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server T
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server w
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue
A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Thi
A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46
A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function
A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cp
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes
NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office S
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile()
Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to
A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially craf
OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) mi
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl
KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrar
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi
ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vuln
A weakness has been identified in Microweber up to 2.0.20. This affects the function userfiles_path of the file /api_nos
A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown functi
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/Pa
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read f
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunder
Incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 152, Firef
In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to loca
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin). Supporte
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Leve
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK vers
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file lite
A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affecte
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorize
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension packa
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started