57,566 vulnerabilities published in 2026
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the functi
In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysf
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versi
Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who ha
Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rend
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the fi
A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function insertPlatformConfig of the file jshERP-b
In the Linux kernel, the following vulnerability has been resolved: pseries/papr-hvpipe: Fix race with interrupt handle
SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai
A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an au
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati
A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of t
Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF
Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who ha
Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfre
pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_
Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to re
A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::exec
dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handl
In the Linux kernel, the following vulnerability has been resolved: ice: fix race condition in TX timestamp ring cleanu
In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix unmap race with PMD migration entr
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had com
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the fi
GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util
A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin
Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unau
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 1
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a re
In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a
The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that,
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request
ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview dep
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar
The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template
Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started