57,566 vulnerabilities published in 2026
Authentication bypass in the password recovery feature of the local web interface across multiple VIGI camera models all
Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload
Pepr is a type safe K8s middleware. Prior to 1.0.5 , Pepr defaults to a cluster-admin RBAC configuration and does not ex
GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extend
Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site
Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and pr
The extension extends TYPO3’ FileSpool component, which was vulnerable to Insecure Deserialization prior to TYPO3-CORE-
Stored Cross-Site Scripting (XSS) vulnerability in Sesame web application, due to the fact that uploaded SVG images are
Reflected Cross-Site Scripting (XSS) vulnerability in Riftzilla's QRGen. This vulnerability allows an attavker to execut
HTML Injection vulnerability in Isshue by Bdtask, consisting os an HTML injection due to a lack os proper validation
Reflected Cross-Site Scripting (XSS) vulnerability in IsMyGym by Zuinq Studio. This vulnerability allows an attacker to
HTML injection vulnerability in multiple Botble products such as TransP, Athena, Martfury, and Homzen, consisting of an
A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open
Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various
A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secre
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not b
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigat
The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigati
When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messa
User-controlled header names and values containing newlines can allow injecting HTTP headers.
Authentication Bypass by Primary Weakness vulnerability in Jamf Jamf Pro allows unspecified impact.This issue affects Ja
ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in
ManageIQ is an open-source management platform. A flaw was found in the ManageIQ API prior to version radjabov-2 where a
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java ap
Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows.
Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by
MacOS version of Inkscape bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permis
EduSoho versions prior to 22.4.7 contain an arbitrary file read vulnerability in the classroom-course-statistics export
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and e
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and e
VB-Audio Matrix and Matrix Coconut (versions ending in 1.0.2.2 and 2.0.2.2 and earlier, respectively), contain a local p
VB-Audio Voicemeeter, Voicemeeter Banana, and Voicemeeter Potato (versions ending in 1.1.1.9, 2.1.1.9, and 3.1.1.9 and e
The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally con
A low-privileged user can bypass account credentials without confirming the user's current authentication state, which m
An Authorization Bypass Through User-Controlled Key vulnerability in Hubitat Elevation home automation controllers prior
The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when seria
Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae4
Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of m
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipu
On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen
Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn
An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. Th
Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The pass
A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy
The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is t
The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is
The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done
The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started