57,566 vulnerabilities published in 2026
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0,
HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX CMS is vul
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed
In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An
An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN t
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent at
An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN t
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with Wi
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges o
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnera
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab
A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could wri
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aida Computer Info
Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versi
A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user in
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a hardcoded credential in th
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.
Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.
Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Aut
The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users t
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjace
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attack
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack
FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cro
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent a
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tdpserver modules) allows adjacent attackers to ca
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started