57,566 vulnerabilities published in 2026
SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code
SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing quer
SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls
SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations,
SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or names
SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements includin
SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain e
SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on em
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi
A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the compone
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value be
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i
A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The int
SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server
SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references.
SurrealDB versions before 3.1.0 contain a denial of service vulnerability where malicious LIVE queries with WHERE clause
SurrealDB before 3.1.0 evaluates user-supplied WHERE clauses in SELECT statements (and SET/MERGE/CONTENT/PATCH clauses i
SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annot
SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcin
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enfo
ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-r
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name`
Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a
NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the fi
In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attac
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped fil
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tr
The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated tr
A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), v
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large leng
Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callb
Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability tha
Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one wo
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP
Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-mi
FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Req
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started