57,566 vulnerabilities published in 2026
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can l
A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the f
The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi
A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-head
Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control S
A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function
A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts
Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 1
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes
Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/s
Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attach
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-stre
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer
Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go rea
Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALO
The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on a
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict acc
The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its p
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.
An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of serv
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification m
The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events
The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which RE
The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in req
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the logi
There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remot
CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without aut
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8
The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauth
The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway w
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e
AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthentica
NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid
The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a
A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the f
Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unenco
A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of t
NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers
The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an aut
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u
HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or creden
The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started