57,566 vulnerabilities published in 2026
Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful
UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tor
A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th
Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is s
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload
The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where
AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggere
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.26
WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded
Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio
HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat
HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac
CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dc
OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limit
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticate
The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the tem
A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this is
GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by th
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to
HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information
HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking i
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated atta
Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode()
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as Date
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a
IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through
OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_cont
IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error messag
@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static file
A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file a
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of th
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of
A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction
A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` a
SurrealDB versions before 3.1.0 fail to apply the SURREAL_WEBSOCKET_MAX_MESSAGE_SIZE limit to anonymous /sql WebSocket c
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started