57,566 vulnerabilities published in 2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls M
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, B
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenti
RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to
RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key fil
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Althoug
Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositor
Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from
CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their res
CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective releas
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versio
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used
Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GH
Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as fu
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows
Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who
The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requ
The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user
The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the syste
The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() functi
The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syn
The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to se
The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user
The extension passes an editor-configurable email subject string directly into a Fluid template source without restricti
The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control
When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encr
The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the prof
The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a re
The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly i
The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged b
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserial
The extension fails to validate a client-supplied template element key before using it to build file paths for saving an
The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in
The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and
The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for c
The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modi
The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the
The permission check for the frontend management update flow verified a different event than the one the request went on
The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-exi
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin per
Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork develop
A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to e
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agen
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping i
Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A miss
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started