57,566 vulnerabilities published in 2026
Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and
Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Reque
During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in clearte
Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at
Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' fo
The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable()
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio
Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands,
Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker t
FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to b
FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived f
FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-
Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribut
Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attri
Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action att
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defens
The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenced an endp
The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile ima
Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in pac
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Sec
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).
The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 2
The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service
Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe
A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is
In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive con
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data a
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensiti
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec
The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to in
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started