57,566 vulnerabilities published in 2026
Out of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentiall
Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory
Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker
Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i
Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inform
Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker lev
Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social eng
Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside
Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering
Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtai
Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to
Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informatio
Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive info
LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in int
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before p
The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin bef
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of
The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named i
GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 1
Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mecha
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header
Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in ma
Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp
Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endp
libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexe
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels
Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple M
Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as th
Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used i
Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerab
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the c
The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an at
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these m
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Fu
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving
Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read a
FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the
The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute i
libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js u
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and
When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing th
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserv
The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding i
A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver
Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started