57,566 vulnerabilities published in 2026
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet
The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization
Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer
Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and e
The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchi
The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po
Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke
The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir
Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dy
The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read whe
The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside
Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may
A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configu
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affec
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arb
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible l
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOT
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configure
Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of pr
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against El
The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputti
filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated u
Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant exec
Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thund
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started