57,566 vulnerabilities published in 2026
DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a
Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function
AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows aut
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()
The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards Serv
Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.Act
In the Linux kernel, the following vulnerability has been resolved: USB: serial: io_ti: fix heap overflow in get_manuf_
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e
Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,
Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 51
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, an
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the
Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automati
The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML a
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t
An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via
A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass
Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat
Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.
n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances confi
OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skippe
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Str
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges wi
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a phy
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a p
Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attac
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-acces
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilit
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:re
Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4
Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the v
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started