57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length t
In the Linux kernel, the following vulnerability has been resolved: ceph: fix pre-auth out-of-bounds read on snaptrace
In the Linux kernel, the following vulnerability has been resolved: sctp: close UDP tunnel sockets during netns teardow
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix stale skb->sk reference on subflow close
In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk
In the Linux kernel, the following vulnerability has been resolved: amt: re-read skb header pointers after every pull
In the Linux kernel, the following vulnerability has been resolved: ksmbd: pin conn during async oplock break notificat
In the Linux kernel, the following vulnerability has been resolved: s390/checksum: Fix csum_partial() without vector fa
In the Linux kernel, the following vulnerability has been resolved: smb/client: handle overlapping allocated ranges in
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol pars
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated re
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no v
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to ex
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the ne
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a networ
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.proper
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its re
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access
The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor
The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. A
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file sys
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the syst
Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: befo
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutr
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflo
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an
The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coor
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-esc
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-veri
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started