57,566 vulnerabilities published in 2026
The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters a
Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and p
The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,
Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation
Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on i
A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud C
Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow.
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NP
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router mod
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patc
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, wh
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass v
Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t
Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. Thi
Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause
DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that
FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version
FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Temp
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authentica
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference
Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑gener
A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log d
The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 unti
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a
FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online s
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-constructi
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authentic
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the client-side hashRedirect plugin calle
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, Public shared-view endpoints exposed valu
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared-view password check fell back
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, sign-in response timing differed between
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a user in one workspace could exercise an
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the connection-test endpoint opened a raw
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HT
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with column-create
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated user with base-create pe
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, two concurrent token-exchange requests us
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (pack
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with kno
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users s
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-fetch endpoint (axiosRequ
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a passwor
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authe
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the base-migration endpoint accepted a ca
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started