57,566 vulnerabilities published in 2026
ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstan
Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an
rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows atta
Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registra
A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the
A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/custome
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function sa
A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing o
A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of th
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the fil
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor
The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated requ
A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _trans
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown
DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate optio
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL po
Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary scrip
A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/ja
In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attack
Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no tru
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core
Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unva
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated empl
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an e
Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback en
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied dur
Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attack
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive i
A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a
EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermet
Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.
Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a cont
Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started