57,566 vulnerabilities published in 2026
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be
A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.4 and iPadOS 26.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonom
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sen
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS So
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, mac
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Ta
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia
The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP arch
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software
Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icon
Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue
Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This is
n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without
A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excess
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1
The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up t
The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated u
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This i
Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a
MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `m
Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/all
Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects
Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil
MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a h
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for
When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s
A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.ph
WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, a
Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticat
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint,
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_ap
LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoi
The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started