57,566 vulnerabilities published in 2026
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerab
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the c
The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an at
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these m
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Fu
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving
Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read a
FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the
The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute i
libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js u
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and
When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing th
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserv
The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding i
A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver
Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs
Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & L
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain
An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU dispr
An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal ha
An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression st
An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its
gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs w
wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce
Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoo
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attack
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing una
R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authen
Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset e
Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when
StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfi
Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c vali
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints
The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling be
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation che
pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token vali
Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-
A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks
WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php tha
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started