57,566 vulnerabilities published in 2026
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acrofor
OpenList Frontend is a UI component for OpenList. Prior to 4.1.10, certificate verification is disabled by default for a
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, the OAuth 2.0 implementation for
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere
A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the
SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain de
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to
An arbitrary file overwrite vulnerability in the file import process of Comic Book Reader v1.0.95 allows attackers to ov
n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploade
OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and electio
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegat
Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in th
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is n
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target ema
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attack
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.
A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the prom
LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymak
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local bl
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a ma
Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the
The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in
eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the deleteUserAccount JSON-RPC
A security flaw has been discovered in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. Affected by this vulnerability is an u
IBM DataStage on Cloud Pak for Data 5.1.2 through 5.3.0 returns sensitive information in an HTTP response that could be
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attac
Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Incorrect Privilege Assignment vulnerability. A
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method al
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acrofor
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.
SPIP before 4.4.9 allows Insecure Deserialization in the public area through the table_valeur filter and the DATA iterat
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started