57,566 vulnerabilities published in 2026
Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulnerability allows phys
Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physica
Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows physically present attac
VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in
The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it in
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom
The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allow
An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert
A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may
Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (form
The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open
NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator co
NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS com
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP se
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputtin
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th
Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spri
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is expose
mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in serv
pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServ
tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/htt
tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src
openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choos
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly saniti
gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where cr
Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can in
Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that
Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint th
Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry pat
The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, al
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of priv
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil
In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privile
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if
In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Qu
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Se
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started