2026
57,566 vulnerabilities published in 2026
A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker t
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i
This vulnerability allows authenticated attackers to execute commands via the hostname of the device.
Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname
XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a
Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthe
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sa
The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS sys
Incorrect Privilege Assignment vulnerability in Modular DS modular-connector allows Privilege Escalation.This issue affe
A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (compo
Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a W
Unrestricted Upload of File with Dangerous Type vulnerability in garidium g-FFL Checkout g-ffl-checkout allows Upload a
File Upload vulnerability in TMS Global Software TMS Management Console v.6.3.7.27386.20250818 allows a remote attacker
Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Bire
SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `Async
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user
Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged us
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ whic
Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive app
A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The
The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authe
This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file
During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th
Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to p
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.val
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtain
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch
EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water dis
A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows
Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl
A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu
The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. Thi
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis
Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis
Sensitive data disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cy
PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metac
Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Versions 34.0 through 50.0 arevulnerable to arbitrary
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin ver
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed i
Sandbox escape in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started