57,566 vulnerabilities published in 2026
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to e
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 1
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom oper
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary v
Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in ver
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful expl
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-prov
TOTOLink X5000R v9.1.0cu_2415_B20250515 contains an OS command injection vulnerability in the setIptvCfg handler of the
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 1
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `ja
Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorizat
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attac
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated atta
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker t
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenti
Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be execute
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (
The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to
Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exis
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated a
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track
Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. T
Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerabilit
Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabi
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the se
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started