57,566 vulnerabilities published in 2026
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.
Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-leve
rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allow
rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope o
rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a ma
rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is use
rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows
vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions Complet
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creat
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Repository migration SSRF via multi-answer DNS allow-list bypass
The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-bas
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manage
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads
Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started