57,566 vulnerabilities published in 2026
SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video pa
The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. Th
The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized in
The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter.
A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenat
The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id
Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without res
Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing at
Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segme
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_hand
A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c2
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg()
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmen
An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain
An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr
An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of
An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a
Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of
An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafte
An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE
An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafte
Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cau
An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to
Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers
A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Deni
An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a
An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted
A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (D
An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Se
Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application open
Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fai
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functiona
An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/captu
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticate
In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading t
Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue acr
Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authori
Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint a
Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: *
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This m
Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That doe
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnera
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. Th
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <=
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started