57,566 vulnerabilities published in 2026
Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 an
libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur
BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentation
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, a
SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vul
Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulne
The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' p
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows auth
ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not
Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, au
Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configure
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /c
PLANET GS-4210-16P2S firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities
PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer derefere
PLANET GS-4210-16P2S firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-b
The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds th
SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*pa
The Quiz Maker WordPress plugin before 6.7.0.89 does not sanitise and escape some of its settings, which could allow hig
e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload ma
A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Face
Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, cu
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Iden
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
Cross-site scripting vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation. If a
mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01
CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with adm
Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when d
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE
Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE
Saleor is an e-commerce platform. Starting in version 3.0.0 and prior to versions 3.20.108, 3.21.43, and 3.22.27, Saleor
Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function atte
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restri
A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote atta
FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload S
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnera
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a s
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, the
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started