2026
57,566 vulnerabilities published in 2026
Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack
Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at
Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering acc
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfe
A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.2
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action request
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable
A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role hold
Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId
The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend
In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation cri
The cohttp package before 6.3.0 for OCaml allows directory traversal.
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read acc
Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large arr
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read acc
Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impe
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attack
The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custo
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files ext
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of custome
The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting th
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape v
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simp
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban all
Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who s
Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriag
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application t
SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element
Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name t
Deserialization of Untrusted Data vulnerability in ash-project ash_cloak allows an attacker who can influence the bytes
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ash-project ash_cloak allows anyone with acc
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote cl
Incorrect Authorization vulnerability in ash-project ash_graphql allows an authenticated subscriber in one tenant to rec
Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay nod
Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_graphql allows an unauthenticated
Incorrect Authorization vulnerability in ash-project ash_graphql delivers GraphQL subscription payloads for records a su
Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolv
Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthentic
Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-r
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider requ
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-conf
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can infl
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal erro
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started