57,566 vulnerabilities published in 2026
The underlying PLC of the device can be remotely influenced, without proper safeguards or authentication.
Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write f
delpino73 Blue-Smiley-Organizer 1.32 contains an SQL injection vulnerability in the datetime parameter that allows unaut
microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary
Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate
XOOPS CMS 2.5.9 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database que
NoviSmart CMS contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by i
WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri
Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database qu
DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database q
Web Ofisi Rent a Car v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate data
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `code
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b
Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `reada
Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, whe
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s
Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids inse
Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries
Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries
Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie
Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie
Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database querie
Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attac
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database q
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database q
osCommerce 2.3.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database q
kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in vers
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Fo
wpForo 2.4.14 contains an unauthenticated SQL injection vulnerability in Topics::get_topics() where the ORDER BY clause
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL
Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database q
Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database q
Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database q
Simple Job Script contains an SQL injection vulnerability that allows attackers to manipulate database queries by inject
NCrypted Jobgator contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database q
FreeSMS 2.1.2 contains a boolean-based blind SQL injection vulnerability in the password parameter that allows unauthent
Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate
Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elemento
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti
Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL
BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri
Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit
Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthen
DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri
EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by
Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri
Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database informa
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started