57,566 vulnerabilities published in 2026
Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through
The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set uncondit
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prio
A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall o
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A m
Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attac
The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register(
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass i
The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass i
vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decod
Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON seri
Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows una
Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strin
Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication ru
rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a
rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization an
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, al
Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 f
Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r
Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compro
Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive
Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re
Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker
Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th
Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende
Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf
Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineerin
Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re
Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf
Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive in
Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A m
The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (rel
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before r
The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through i
The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored s
The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restr
The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only f
The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed t
The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJA
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal s
CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remot
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started