57,566 vulnerabilities published in 2026
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe
The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. P
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles o
Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,
Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firef
Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate t
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.
Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.
Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.
Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.
Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versi
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in sale
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectiv
WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-
A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php
MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middlewa
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in ser
Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbi
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompress
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via t
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoi
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave st
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require Authorit
The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/
Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message
Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The suppo
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started