Strobes VIStrobes VI
CVE DatabaseThreat ActorsResearchAdvisoryAPI Docs
Visit Strobes.coSign Up for Strobes
CVE DatabaseThreat ActorsResearchAdvisoryAPI Docs
Tools
KB Lookup
Visit Strobes.coSign Up for Strobes

Do you like the insights?

Strobes vulnerability intelligence is a key component of their Exposure Management platform that helps organizations understand, prioritize, and address security vulnerabilities more effectively.

© 2026 Strobes Security. All rights reserved.
HomeExplore CVEs

Explore CVEs

Filter and search through 199,777 vulnerabilities

Filters
0
01000
Showing 20 of 199,777 results
CVE IDDescriptionCVSSPriorityTrendExploitPatch
CVE-2026-25630

The following security vulnerability was identified in jsPDF versions <=3.0.4: [Local File Inclusion/Path Traversal](https://github.com/parallax/jsPDF...

0.00NeutralNo
Page 7
First PageNext
Yes
CVE-2026-25598

## Summary A security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections...

0.00NeutralNoYes
CVE-2026-25579

### Summary Authenticated users can crash the Navidrome server by supplying an excessively large `size` parameter to `/rest/getCoverArt` or to a share...

0.00NeutralNoYes
CVE-2026-25566

WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without a...

0.00NeutralNoYes
CVE-2026-25556

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display...

0.00NeutralNoYes
CVE-2026-25547

### Summary `@isaacs/brace-expansion` is vulnerable to a Denial of Service (DoS) issue caused by unbounded brace range expansion. When an attacker pr...

0.00NeutralNoYes
CVE-2026-25543

### Impact If the `template` tag is allowed, its contents are not sanitized. The `template` tag is a special tag that does not usually render its con...

0.00NeutralNoYes
CVE-2026-25541

# Details In the unique reclaim path of `BytesMut::reserve`, the condition ```rs if v_capacity >= new_cap + offset ``` uses an unchecked addition. Wh...

0.00NeutralNoYes
CVE-2026-25533

**Note:** The npm package has moved to `@enclave-vm/core` (formerly `enclave-vm`). All fixed versions and guidance refer to `@enclave-vm/core`. ###...

0.00NeutralNoYes
CVE-2026-25522

## Summary A stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs be...

0.00NeutralNoYes
CVE-2026-25521

### Summary A Prototype Pollution vulnerability exists in the the npm package locutus (>2.0.12). Despite a previous fix that attempted to mitigate Pro...

0.00NeutralNoYes
CVE-2026-25517

### Impact Due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge of a model's fields can c...

0.00NeutralNoYes
CVE-2026-25514

### Summary **FacturaScripts contains a critical SQL Injection vulnerability in the autocomplete functionality** that allows authenticated attackers t...

0.00NeutralNoYes
CVE-2026-25513

### Summary **FacturaScripts contains a critical SQL Injection vulnerability in the REST API** that allows authenticated API users to execute arbitrar...

0.00NeutralNoYes
CVE-2026-25498

## Relationship to Previously Patched Vulnerability This vulnerability is **in addition to** the RCE vulnerability patched in [GHSA-255j-qw47-wjh5](h...

0.00NeutralNoYes
CVE-2026-25497

There is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user with write access to one asset volume to es...

0.00NeutralNoYes
CVE-2026-25496

## Summary A stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the `|md|raw` Twig fi...

0.00NeutralNoYes
CVE-2026-25495

## Summary The `element-indexes/get-elements` endpoint is vulnerable to **SQL Injection** via the `criteria[orderBy]` parameter (JSON body). The appl...

0.00NeutralNoYes
CVE-2026-25494

I observed a [recent commit](https://github.com/craftcms/cms/commit/9d9b46a9e40cbdfb20d0d933abb546be12ccd3af) intended to mitigate Server-Side Request...

0.00NeutralNoYes
CVE-2026-25493

## Summary The `saveAsset` GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows HTTP redirects ...

0.00NeutralNoYes