57,566 vulnerabilities published in 2026
Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co
An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (wi
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma
In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS So
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S
Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local a
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerabi
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to versio
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SS
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a v
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231)
The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's
Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of t
nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header function of the Modbus/TCP serv
When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearc
Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File Upload & Countr
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configu
An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the r
Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator i
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be u
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers
Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions.
Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions.
Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Pat
DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor
http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middlewar
Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm e
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF de
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerabilit
Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal at
Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp c
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when us
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions
In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX data at the hardware packet off
An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject pe
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started