57,566 vulnerabilities published in 2026
The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization.
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folde
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API
In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client
Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue ap
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a con
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validat
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Seres Software syW
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connecti
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatic
darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's
Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then rende
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advan
Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site na
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software I
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics
A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the
A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not
A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed)
A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the G
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer
pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-p
WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint
WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administ
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
A vulnerability in the read-only maintenance shell of Cisco Intersight Virtual Appliance could allow an authenticated, l
Directory Traversal vulnerability in Beam beta9 v.0.1.521 allows a remote attacker to obtain sensitive information via t
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on L
IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 could all
Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with s
Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect av
Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x withi
Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring
Loop with unreachable exit condition ('infinite loop') for some Intel(R) Platform within Ring 0: Kernel may allow a deni
Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14
A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (AS
A vulnerability in the CLI of Cisco Secure FTD Software could allow an authenticated, local attacker to execute arbitrar
A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authe
A vulnerability in the CLI of Cisco Secure FTD Software could allow an authenticated, local attacker to execute arbitrar
A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software co
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA
OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run appro
OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts al
ChurchCRM is an open-source church management system. Prior to 6.5.3, it is possible to trigger server-side HTTP/HTTPS r
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started