57,566 vulnerabilities published in 2026
SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting S
Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate
Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication b
ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL comma
KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_ite
qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information b
OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers t
WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows u
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memo
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-
The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirm
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Hand
Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.hea
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80
Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that c
act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Co
Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att
Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all
Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in app
DbGate is cross-platform database manager. From version 7.0.0 to before version 7.1.5, a stored XSS vulnerability exists
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decod
In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PC
Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical
ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL
News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da
qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL c
PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database quer
CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries
eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator
Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attac
C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated a
Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to exec
OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database qu
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injec
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injec
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injec
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injec
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injec
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injec
Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injec
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbi
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM).
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to w
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started