57,566 vulnerabilities published in 2026
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose
Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyG
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacke
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r
The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat
The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing c
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF token
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in al
Easy2Pilot 7 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized user accounts
An authenticated attacker's undisclosed requests to BIG-IP iControl REST can lead to an information leak of BIG-IP local
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can oc
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment b
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, an
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and
GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 5.3.2
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server
Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau
Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints
DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize
HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. Th
CWE-601 URL redirection to untrusted site ('open redirect')
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with m
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset,
Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote at
Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to
Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an
Integer overflow in Internationalization in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker t
Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to
Side-channel information leakage in Navigation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to lea
Insufficient policy enforcement in IFrame Sandbox in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote a
Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacke
Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an ou
Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote att
The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to una
The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1
CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrar
phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIs
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started