57,566 vulnerabilities published in 2026
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send
Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally
The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut
An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with
An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permissi
Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification f
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their
Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data
Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthent
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follo
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handl
Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consume
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and larg
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumpti
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functi
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction han
An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification cou
XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to
Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried
In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X ser
In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Put vmcs12 pages if nested VM-Enter fail
CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to f
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is lo
Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands wi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started