57,566 vulnerabilities published in 2026
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Uni
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
Crafted zones can lead to increased incoming network traffic.
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security v
FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessi
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these op
The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Obj
A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not
A vulnerability was found in ckolivas lrzip up to 0.651. This impacts the function lzma_decompress_buf of the file strea
Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before vers
Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Author
Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled,
Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, poten
JUNG Smart Panel KNX firmware version L1.12.22 and prior contain an unauthenticated path traversal vulnerability in the
The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to,
The WPZOOM Addons for Elementor – Starter Templates & Widgets plugin for WordPress is vulnerable to unauthorized access
An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/us
An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0,
A path-traversal vulnerability in the logout functionality of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to unauthorized a
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the publi
The firmware update functionality does not verify the authenticity of the supplied firmware update files. This allows at
webtransport-go is an implementation of the WebTransport protocol. From 0.3.0 to 0.9.0, an attacker can cause excessive
webtransport-go is an implementation of the WebTransport protocol. Prior to v0.10.0, an attacker can cause a denial of s
webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memo
Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enu
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attac
A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted H
The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versi
The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec
The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,
The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data
The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing c
The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including
The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missi
A security flaw has been discovered in Open5GS up to 2.7.6. This vulnerability affects the function ogs_gtp2_parse_tft i
A weakness has been identified in Open5GS up to 2.7.6. This issue affects the function sgwc_s5c_handle_create_session_re
A security vulnerability has been detected in Open5GS up to 2.7.6. Impacted is an unknown function of the file /src/mme/
A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_conte
A flaw has been found in Open5GS 2.7.6. The impacted element is the function mme_s11_handle_create_session_response of t
A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoi
The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started