57,566 vulnerabilities published in 2026
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decaps
TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src
Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin mid
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a networ
The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived e
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(repo
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned get
The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before renderin
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 h
Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged t
Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-co
PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and a
Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonl
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay mo
WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in th
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compa
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerab
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validat
adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforc
TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arb
Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9,
rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitra
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account w
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint t
An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC sof
Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers
Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticate
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection
Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to vali
Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing
Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --co
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional refere
The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0
A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with a
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentica
Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or ra
Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated us
Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write opera
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _
An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under speci
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started