57,566 vulnerabilities published in 2026
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, b
FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel'
Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated r
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome ex
Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.11
Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
Off-by-one error in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social enginee
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security
Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earli
Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST v
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Bro
Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an
An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log
The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mc
Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by
In the Linux kernel, the following vulnerability has been resolved: perf tools: Use perf_env__get_cpu_topology() in mac
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free
Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticat
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in sr
plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiv
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL state
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path b
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in toke
A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of t
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending
This vulnerability allows a Backup or Tape Operator to write files as root.
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe
Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane
A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitizati
Altium 365 workspace endpoints were configured with an overly permissive Cross-Origin Resource Sharing (CORS) policy tha
hustoj is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. All versions are vuln
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started