57,566 vulnerabilities published in 2026
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attacke
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by
Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig opti
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker
IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header par
All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execu
picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _ai
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in t
The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a
The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounti
In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender va
Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attacke
In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crus
In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_st
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strto
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() er
In the Linux kernel, the following vulnerability has been resolved: tipc: fix double-free in tipc_buf_append() tipc_ms
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching sad
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb2_open during durab
In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The cod
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qual
In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_l
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-fre
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmg
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb
concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock doe
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request va
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI t
Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request pa
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQ
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table
In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir
In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADE
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer
In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_
In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offlo
In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COO
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in m
In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started