57,566 vulnerabilities published in 2026
A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer derefere
Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows a
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file c
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage retur
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of re
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-o
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to impro
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decaps
TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src
Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin mid
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a networ
The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived e
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(repo
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned get
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before renderin
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 h
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged t
Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-co
PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and a
Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonl
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay mo
WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in th
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compa
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerab
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validat
adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforc
TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arb
Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9,
rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitra
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account w
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint t
An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC sof
Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers
Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticate
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started