57,566 vulnerabilities published in 2026
The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due
Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if th
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a com
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Intal Sta
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pondol Pondol BBS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SEOSEON EUROPE S.L
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu Owl Caro
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Im
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption d
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Statsenko
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Logo Sli
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ability, Inc Web A
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jagdish1o1 Delay R
A reflected cross-site scripting (XSS) vulnerability in ToDesktop Builder v0.33.1 allows attackers to execute arbitrary
A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for t
A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in min
Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an un
Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decomp
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 a
vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry
Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made b
The DDNS update function in ADM fails to properly validate the hostname of the DDNS server's TLS/SSL certificate. Althou
The API communication component fails to validate the SSL/TLS certificate when sending HTTPS requests to the server. An
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP respon
Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inc
Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isC
A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) s
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with con
cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc
Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerabi
A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a car
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS
Pion DTLS is a Go implementation of Datagram Transport Layer Security. Pion DTLS versions v1.0.0 through v3.0.10 and 3.1
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used
IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 IBM Db2 Recovery Expert for Linux, UNIX and Windows transmits data i
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started