57,566 vulnerabilities published in 2026
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea
nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanit
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauth
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL s
Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a loca
Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital
Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it
The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries,
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular exp
A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar
Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni
Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code e
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/cor
In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front le
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly access
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing
siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthen
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and ge
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymou
SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing a
: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priorit
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)
SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allow
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cach
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/o
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to esca
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to p
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, B
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started