57,566 vulnerabilities published in 2026
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_proce
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBu
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationO
The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess
The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v
The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed
The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu
The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image
The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source
Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi
In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef
A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticat
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3
The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce va
The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of i
The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confiden
The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injec
The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem
The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi
Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e
A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col
In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.
In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatio
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adj
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrat
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its
The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when return
Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th
Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo
Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci
A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.
The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S
Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started