57,566 vulnerabilities published in 2026
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 15
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12,
Firefox for iOS used partial domain matching when attaching cookies to PDF requests, allowing a malicious site on a suff
OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a
OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t
OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparison
In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory
In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv
In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This cou
Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments vi
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and
Insertion of sensitive information into sent data vulnerability in MarketingFire Widget Options allows Retrieve Embedded
Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security
Subscriber Broken Access Control in Genemy <= 1.6.6 versions.
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten
Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain pot
Unauthenticated Deserialization of untrusted data in Slimstat Analytics < 5.4.0 versions.
Subscriber Arbitrary Content Deletion in WPAMS < 49.5.3 versions.
CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do
Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access.
Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover
Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote un
Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake th
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web In
Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut
Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or
Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level pri
The postman_download module uses the workspace name field from the Postman API to construct the local directory path wit
LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started