57,566 vulnerabilities published in 2026
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system v
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module doe
This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic
This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in i
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset conf
This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable t
A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplie
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names,
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_she
Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` whi
The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp im
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior
OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site s
The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 throug
An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attack
A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticat
The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization chec
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0
HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF)
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vu
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` functio
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper se
A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of
A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Ser
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file upl
A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and A
On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensit
A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device
A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficie
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled
An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper han
This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController compo
Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such a
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a c
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutra
MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potentia
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sa
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started