57,566 vulnerabilities published in 2026
Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allo
Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verifi
Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the rend
Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potenti
Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members sign
Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo
Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, an
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of bei
An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have
This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative
An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured wit
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Docum
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPath
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a
The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only re
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/en
Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 pr
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing t
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s,
Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildca
Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to ha
A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allow
Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin
The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose se
When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing E
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path travers
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying pr
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.
Unauthenticated Sensitive Data Exposure in WCBoost – Products Compare <= 1.1.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu
A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function
A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile o
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started