57,566 vulnerabilities published in 2026
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipar
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authe
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to exec
LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or ma
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object informat
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS)
LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user upda
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset re
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce che
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() retur
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle m
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Serialize accesses to the owner and mirro
In the Linux kernel, the following vulnerability has been resolved: vxlan: do not arm the ageing timer on a device that
In the Linux kernel, the following vulnerability has been resolved: net/dibs: Correct freeing of dmb_clientid_arr A di
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix missing shared-key auth cha
In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: fix TX DMA buffer flush When tr
In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before stoppi
In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: reject feature changes after endpoint
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and
The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formCo
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an un
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 expos
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory
The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring
Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission gu
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versio
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that all
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as
Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote
The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functiona
Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in RequireSc
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated co
Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class
NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user
QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, sche
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started