57,566 vulnerabilities published in 2026
Subscriber Broken Access Control in Motors <= 1.4.113 versions.
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.
rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-leve
rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allow
rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope o
rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a ma
rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is use
rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows
vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions Complet
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creat
Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Repository migration SSRF via multi-answer DNS allow-list bypass
The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-bas
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC
Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).
Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manage
Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc
Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads
Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial
Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipu
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All
Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service
Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Co
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on manag
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A
Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker
Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva
Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied inpu
Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kiba
A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en
A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-
A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized oper
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started