57,566 vulnerabilities published in 2026
Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convin
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The gene
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29,
Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a m
Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an u
LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel.
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections
This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on t
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string
Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes use
Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a ma
An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand)
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper N
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packe
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the
GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici
Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is
vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions
vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon
The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamica
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File Syst
A heap buffer over-read vulnerability was discovered in libsoup's (versions: libsoup 3.0 to 3.7.0) HTTP/2 connection tra
A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory con
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.
FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can
CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg
Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters usi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started