57,566 vulnerabilities published in 2026
SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attack
The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user
In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-
In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.
A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to injec
An embedded test key and certificate could be extracted from a Poly Voice device using specialized reverse engineering t
The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attac
Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (
Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: D
Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.
QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, w
Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on a
FreshRSS is a free, self-hostable RSS aggregator. From 57e1a37 - 00f2f04, the lengths of the nonce was changed from 40 c
Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be i
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code exec
rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical
RenderBlocking is a MediaWiki extension that allows interface administrators to specify render-blocking CSS and JavaScri
Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops
Improper buffer restrictions in some UEFI firmware for some Intel(R) reference platforms may allow an escalation of priv
Improper input validation in the UEFI WheaERST module for some Intel(R) reference platforms may allow an escalation of p
Time-of-check time-of-use race condition in the WheaERST SMM module for some Intel(R) reference platforms may allow an e
Improper input validation in the UEFI FlashUcAcmSmm module for some Intel(R) reference platforms may allow an escalation
Improper input validation in the UEFI ImcErrorHandler module for some Intel(R) reference platforms may allow an escalati
Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an infor
Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege.
Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation
Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an inform
Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an in
Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attac
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t
An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta
An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulne
An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can
An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privi
Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-F
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks
In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged u
soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (
Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker
Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webs
Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms -
Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an admini
The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met
Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover
Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user
Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/administracion/
Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuari
Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests w
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started