57,566 vulnerabilities published in 2026
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.
An unauthenticated user may access restricted repository information under specific conditions.
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co
An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in
An unauthenticated user may bypass authentication under specific cache conditions.
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions req
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 1
An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow
SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that retu
Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the fa
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session wi
Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of servic
vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_functi
The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-statu
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protect
: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence
Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.
Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-al
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that al
rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remot
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex paramet
vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x *
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends
Private Repository Existence Disclosure via go-get Meta Endpoint
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request t
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a buffer
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DR
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitializ
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when pro
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bo
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST
A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadR
A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin
A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of th
Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of
A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method p
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started