57,566 vulnerabilities published in 2026
Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack. This issue affects A
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apach
The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 t
nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these fun
nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its no
cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the
Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix d
undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or priva
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a w
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation against brute-force a
The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-fo
An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cau
LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thr
FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-si
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B
A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials assoc
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t
A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing al
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa
A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec
The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log en
GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause un
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications,
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could
A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D
The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo
The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the
The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started