57,566 vulnerabilities published in 2026
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf
Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend d
Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, pass
CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communicatio
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versi
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_b
A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms
stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP co
Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional a
Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access
The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directl
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arb
The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql para
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries admin
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before
An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concaten
An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /c
Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/web
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy
DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize th
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which l
AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid f
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation wor
LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable
A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticate
Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as r
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacemen
SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an exter
KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API
KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not
In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-sc
“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a
A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service i
Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Eve
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - bui
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.
Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The admin
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An att
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF e
Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. Whil
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started