57,566 vulnerabilities published in 2026
A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le
The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as crypt
CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device info
The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" a
A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.
Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than c
Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic o
HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate th
Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specia
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simula
The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploi
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unau
An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privi
A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a loca
A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Malici
Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hy
A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with admi
mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRe
My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJA
Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals
GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access cont
mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul
next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoin
ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::ge
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint va
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to
When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separ
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP f
Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vu
Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present i
Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execu
The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the dat
SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve,
Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint th
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerabili
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that all
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin da
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quaranti
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administr
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user das
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr
Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing
Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configurati
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started