57,566 vulnerabilities published in 2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover
Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote un
Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake th
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web In
Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut
Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a
When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or
Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level pri
The postman_download module uses the workspace name field from the Postman API to construct the local directory path wit
LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue
libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryC
PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows
An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related
An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing l
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln
The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary
The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, a
A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read p
Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configuration
There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects G
libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder valid
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut
Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kes
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized at
Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-
The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr
AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that
Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that
Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users
Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the ex
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authen
IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 th
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit M
Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to
Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started