57,566 vulnerabilities published in 2026
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served t
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served
Privilege Escalation via Access Token Scope Escalation in API
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allow
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for C
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper co
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adj
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default Cr
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authent
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 th
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without aut
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/document
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensit
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control o
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in
In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __i
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong ipv6 transport off
In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with an out-of-range payl
In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq structs in ip_vs_conn_ne
In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry size 64-bit in fil
In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix partial se
In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruption with header-split
In the Linux kernel, the following vulnerability has been resolved: net: mana: Sync page pool RX frags for CPU MANA al
In the Linux kernel, the following vulnerability has been resolved: net: mana: Validate the packet length reported by t
In the Linux kernel, the following vulnerability has been resolved: locking/rt: Fix the incorrect RCU protection in rt_
In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI ISID use-after-free i
In the Linux kernel, the following vulnerability has been resolved: scsi: target: Bound PR-OUT TransportID parsing to t
In the Linux kernel, the following vulnerability has been resolved: dm-verity: fix buffer overflow in FEC calculation
In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: handle inline data with a nonzero offse
In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: reject short AUTH_RECEIVE buffers nvme
In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send erro
In the Linux kernel, the following vulnerability has been resolved: tcp: defer md5sig_info kfree past RCU grace period
In the Linux kernel, the following vulnerability has been resolved: ntfs: fix WARN_ON for resident attribute in ntfs_ma
In the Linux kernel, the following vulnerability has been resolved: ntfs3: validate split-point offset in indx_insert_i
In the Linux kernel, the following vulnerability has been resolved: ntfs3: bound to_move in indx_insert_into_root befor
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: add depth limit to indx_find_buffer to pr
In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident index root values on lookup
In the Linux kernel, the following vulnerability has been resolved: ntfs: detect mapping-pairs LCN accumulator overflow
In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index entries on reading Validate i
In the Linux kernel, the following vulnerability has been resolved: ntfs: validate index block header more strictly Mo
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started