57,566 vulnerabilities published in 2026
Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendere
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-u
Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in th
Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, w
HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthori
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements v
UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI ele
UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever
UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI el
UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address ba
UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core
Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PA
The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a us
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitiz
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTa
The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In t
Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applica
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnera
RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frame
An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the paren
An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capt
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to
A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write pat
Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.
The affected Ebyte device web management interface does not restrict the interface from being rendered within an extern
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th
A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when pro
xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript v
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Sof
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attac
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to per
Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission check
Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() i
The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its setti
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT acces
Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started