57,566 vulnerabilities published in 2026
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne
Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Atta
Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A
HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows att
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a pa
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Syn
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hash
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incor
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the
Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Ai
Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections wi
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache Acti
CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a
In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead t
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow rem
Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party ori
Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via at
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packe
QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS s
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing en
Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged netwo
Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a use
On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibi
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co
Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decr
Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer derefere
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started