57,566 vulnerabilities published in 2026
pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N
A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/
A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryControl
A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of
A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown functi
Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeave
A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus
Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p
secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th
A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of t
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings o
Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).
DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a diffe
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Don't leak PFN when kvm_translate_vncr(
The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1
A race condition was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 1
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv
Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of
Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att
The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect
A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and
jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl
A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of t
A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunctio
A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_ex
When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started