57,566 vulnerabilities published in 2026
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local Fil
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. T
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when cr
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory g
OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers
Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Serv
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileg
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 t
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had co
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attac
SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu
Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c
The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10.
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, Fo
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted reque
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose in
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disc
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users t
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform sp
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media
A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attacker
An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack overflows in the formSet
lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips
A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F
In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending r
Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on t
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started