57,566 vulnerabilities published in 2026
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i
An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view
OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only
CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the d
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/appli
Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users
The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow
Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within
The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLL
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re
The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against
The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload
Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re
Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `
A repository publisher without delete permission may modify protected package content under specific conditions.
RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, Co
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a
A low-privileged authenticated user may access restricted support information under specific conditions.
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to modify SQL tables due to improper neutraliza
Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to s
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fi
rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary file
A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a
A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds
Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying th
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secr
A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit res
Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoi
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete
GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file an
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started