57,566 vulnerabilities published in 2026
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of th
The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human
Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data
Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an
A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m
Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop
marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat
Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a
Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built
The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje
The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users
The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object
The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to
The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w
changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP
KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl
The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec
Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r
Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t
Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started