57,566 vulnerabilities published in 2026
Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Exte
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that
A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attac
elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results i
Hardcoded Password Vulnerability have been found in CENTUM. Affected products contain a hardcoded password for the user
User enumeration in ESET Protect (on-prem) via Response Timing.
A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in cosmic-greete
AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket
A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIME
SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co
Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack
The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access
A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a vict
Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched
SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dyna
The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. In version 1.2.0 and prio
A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user account
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R2
A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Auto
Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation Mediawiki - Wikilove Extension
Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Ex
An improper access control vulnerability exists in Semtech LoRa LR11xxx transceivers running early versions of firmware
The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability
The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmwa
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun
Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExper
Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki
An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) w
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun
An exposed IOCTL with an insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi
Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and pr
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an a
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that al
Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior
This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service ov
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta
The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper
A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.
ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCR
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the Pay
Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there i
Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability e
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in upKeeper Solutions u
.NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started