57,566 vulnerabilities published in 2026
In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count boun
In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative creden
Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cros
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Nat
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada all
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scrip
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Fr
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automot
The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewal
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, a
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Le
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CleverReach® Cleve
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ichurakov Paid Dow
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unau
Azure Entra ID Elevation of Privilege Vulnerability
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information o
ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malic
In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local
FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled'
Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists
In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to l
The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Coven
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Allma
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Crete
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Elect
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Medin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Nestb
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Saasp
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Woodl
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Wolmart
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Uroan
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TeconceTheme Emerc
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada Download
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker
Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit ev
AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnera
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in don-themes Riode C
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attracti
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos
A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain
Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual as
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started