57,566 vulnerabilities published in 2026
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation funct
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensiti
Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set t
Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname”
Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, wh
Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated
Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including t
Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable
Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer o
Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down whe
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL par
Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An atta
Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send
Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally
The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut
An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass expose
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with
An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permissi
Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:select
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:cre
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification f
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. Th
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their
Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data
Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthent
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici
Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follo
Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation
Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handl
Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consume
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and larg
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumpti
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functi
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started