57,566 vulnerabilities published in 2026
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affecte
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5,
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elev
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Nav
IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special el
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges du
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensit
IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerabil
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could eleva
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injectio
Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to re
IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper val
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper n
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper n
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-hand
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization in
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulner
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an au
Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns,
Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw comm
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that ca
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as t
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to under
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hosti
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing ar
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the oper
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system u
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrar
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLE
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the
Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. Se
SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write v
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic in
A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenti
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started