57,566 vulnerabilities published in 2026
Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge beca
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On all
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to s
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive In
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote atta
The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of
TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's
The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Ent
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extr
In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroo
In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last
In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When c
In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer re
In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal
In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via miss
In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from prima
In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_lock
In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpec
In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions So
In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a neve
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SE
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service d
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac
DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c
Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection,
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanis
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerab
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.
disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fet
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping th
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fr
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the ma
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predi
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started