57,566 vulnerabilities published in 2026
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove
Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vul
Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipA
Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to ret
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advert
Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a null p
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H
Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26
Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in model
Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/att
IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sendin
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::rea
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower-ranked remote moder
Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedl
Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacm
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the rest_propertie
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"
In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation
In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal F
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Quer
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Str
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Str
In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed th
A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer derefere
Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows a
Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file c
Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage retur
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0
Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of re
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-o
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to impro
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started