57,566 vulnerabilities published in 2026
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced
Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rend
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker
Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to obtain potent
Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed a local attacker to bypass n
Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain p
Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass si
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had c
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attack
Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potenti
Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain
Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potent
Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potent
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker
The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field vi
A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-contro
A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlle
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term
The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce chec
A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in t
CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inj
Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Dele
A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor mercha
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The
LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap
LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru
A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar
IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th
SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli
RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_proce
The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain
A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBu
A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationO
The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess
The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v
The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed
The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu
The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-
The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image
The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source
Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started