57,566 vulnerabilities published in 2026
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin
X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLR
Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informa
Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an
Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive infor
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Con
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthe
In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a
In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for examp
The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its bac
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication m
FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_
Several components in Spring Security compare security-sensitive values using standard string equality (String.equals())
ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without strippin
A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing
An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a c
An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin i
An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more tha
filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing at
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a
IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid
IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db
Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an u
Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (S
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to
An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne
The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6
Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request
A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using p
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affec
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affec
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Syne
sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injec
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (C
A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended de
Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may a
The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the
The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started