57,566 vulnerabilities published in 2026
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where th
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the pa
The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart wi
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows admin
The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc
Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.
Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a
The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event descriptio
The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admi
The OPEN-BRAIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' settings field in all
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A hi
The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. Th
OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to prop
The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the
The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up
The Institute Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Enquiry Form Title'
The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in a
The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' setti
The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_c
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistenc
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences.
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's rea
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version
A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attac
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to befo
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path
AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without
CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers
An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link f
The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings
The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via
PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M
Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor befor
Insufficient policy enforcement in Downloads in Google Chrome prior to 148.0.7778.96 allowed a local attacker to bypass
Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 148.0.7778.96 allowed a local
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists
jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-langu
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of
The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,
The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up
An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started