2026
57,566 vulnerabilities published in 2026
Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac
Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack
Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers
Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a
Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate
Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operati
free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handle
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\
Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in
JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 until 1.3.1-beta.2, the PR Branch Checker workflow
WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior to 4.3.5, the sample MySQLBrowserProvider in wsgi
Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URL
PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandEx
StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are su
Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated
Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica
Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at
Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack
Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated at
Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering acc
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfe
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequest
A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.2
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action request
A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable
A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role hold
Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId
The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend
In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation cri
The cohttp package before 6.3.0 for OCaml allows directory traversal.
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read acc
Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large arr
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read acc
Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impe
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attack
The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custo
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files ext
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of custome
The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting th
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape v
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simp
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban all
Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to
Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who s
Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriag
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over
Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started