57,566 vulnerabilities published in 2026
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outpu
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/int
ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/
ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation f
A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the func
A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the fi
OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GE
Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send r
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in
OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls,
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field ty
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.1
Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10
The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 a
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. P
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles o
Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firef
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate t
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versi
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started