57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid hea
In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by
In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STAT
The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, al
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_st
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g.,
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in
DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of th
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remo
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam
rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers t
Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability i
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi inter
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the proces
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated a
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAc
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting do
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When hand
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This mak
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication u
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0
SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which ar
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors wi
QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engin
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauth
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,
Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soci
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the uplo
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize req
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started