57,566 vulnerabilities published in 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extrac
Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corru
phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, al
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authe
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch
Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains
Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, trans
Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped sp
A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-
Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is
In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: reject invalid CCM interval at configu
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().
In the Linux kernel, the following vulnerability has been resolved: ipv6: ndisc: fix NULL deref in accept_untracked_na(
In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - fix OOB read in pefile_di
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bpa10x: avoid OOB read of revision strin
In the Linux kernel, the following vulnerability has been resolved: net: psample: fix info leak in PSAMPLE_ATTR_DATA p
A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the
Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with li
The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` me
Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote
The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of
Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a s
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding
Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated at
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fai
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form proce
Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitra
Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tec
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with acces
Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An atta
Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before in
Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions
Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affec
Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpol
Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-
Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG i
Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering
MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-t
`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index pred
sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite func
sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite agg
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, intern
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, intern
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started