57,566 vulnerabilities published in 2026
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the i
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra
Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se
Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device remo
In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc()
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScript
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap co
Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitra
Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside
Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code i
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitra
Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote
Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code insi
OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin
Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitr
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of t
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the fi
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option
The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data writ
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any au
The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to th
An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execut
A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start probe fa
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ACE size against SID sub-authoritie
In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound DACL dedup walk to copied ACEs set_nt
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn4: avoid rereading IB param length R
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: fix integer overflow in image size
In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the au
In the Linux kernel, the following vulnerability has been resolved: ice: reject out-of-range ptype in ice_parser_profil
In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use-after-free of a severed iucv_path
In the Linux kernel, the following vulnerability has been resolved: geneve: require CAP_NET_ADMIN in the device netns f
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: make release_scratchbuffers idempot
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_stat
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix OOB access from firmware ADDBA wi
In the Linux kernel, the following vulnerability has been resolved: drm/gpusvm: publish dpagemap early to avoid device
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free freeing trigger private
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started