57,566 vulnerabilities published in 2026
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.
An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authentica
Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows
Cross-repository issue/comment attachment re-linking can expose private attachment content
Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Criti
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer
The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request
A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker
A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could downloa
The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request a
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/
An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placi
Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The support
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Publi
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or at
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to the use
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could cause an authentic
In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representation
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, w
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can
aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib
BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and ant
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg rev
SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP
Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a danger
Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sens
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constru
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under diff
There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that m
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that all
It is possible for outbound HTTP requests using a Micrometer-instrumented client to cause a denial-of-service (DoS) cond
A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a C
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started