57,566 vulnerabilities published in 2026
An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that all
** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web ma
The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' p
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3,
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect
Zulip is an open-source team collaboration tool. Prior to 12.0, With message_edit_history_visibility_policy set to "move
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo
The mem0 1.0.0 server lacks authentication and authorization controls for its memory reset and table re-creation functio
The mem0 1.0.0 server lacks authentication and authorization controls for its memory deletion API endpoint (DELETE /memo
Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a netw
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a sec
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose i
requests-hardened is a library that overrides the default behaviors of the requests library, and adds new security featu
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortB
OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to
vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Toke
vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidd
The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers
An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul
The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a
ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files
qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysD
qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysU
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via th
A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program com
An authenticated iControl SOAP user may be able to obtain information of other accounts. Note: Software versions which
When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof thei
Incorrect permission assignment vulnerabilities exist in iControl REST and TMOS shell (tmsh) undisclosed command which m
A vulnerability exists in the undisclosed pages in the Configuration utility that may allow a low-privileged authenticat
An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) network diagnostics command
When embedded Packet Velocity Acceleration (ePVA) acceleration is configured, undisclosed local ethernet traffic can cau
Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and i
A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object id
An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with net
Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacke
Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authent
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's c
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty inc
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attac
The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req
A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur
Any Editor could delete any snapshot, even if they have no access to read or write them.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started