57,566 vulnerabilities published in 2026
A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellBy
Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were
A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options.
Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.
Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.
Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions.
Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu
On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain
Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerabilit
A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenti
pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environm
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to prope
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller sto
Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-exp
A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the
A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the functi
A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects a
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unk
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerabi
A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_ope
A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the
A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_open
A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library
A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of th
A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainf
A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /gofo
A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of th
A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the
A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bi
A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name
A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file
Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clie
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, sever
@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In
The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php ma
mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credent
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk
A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi
A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remov
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_
A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the fi
A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselect
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the f
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of t
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unkn
A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFile
A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of
A security flaw has been discovered in GitBucket up to 4.46.1. This affects the function Git.cloneRepository.setURI of t
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started