57,566 vulnerabilities published in 2026
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Na
A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user acc
An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the pro
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory.
OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID par
Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET re
For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will au
The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scri
A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious
IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially craf
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side
Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protec
Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go use
Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [All
Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do n
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unau
MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-s
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forge
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vul
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated u
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes
Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthor
Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory e
GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-ch
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints
Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter
In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange
In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can conne
Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. Thi
When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, ra
Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permi
Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a qu
Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts
Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web ap
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configure
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication
Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-
A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulne
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-base
This vulnerability in Veeam Service Provider Console allows for remote code execution.
A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to
Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run
Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run
Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it
bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the applicatio
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started