57,566 vulnerabilities published in 2026
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided ba
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the I
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `b
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another c
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across project
Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadat
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties i
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 t
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-b
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privi
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions,
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an in
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-defi
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker t
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDisk
A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgr
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in
SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive informat
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attacker
An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit t
gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain a
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template in
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template in
Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) a
Unintended Proxy or Intermediary vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Network Boundary B
Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import modul
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon
WHILL Model C2 Electric Wheelchairs and Model F Power Chairs do not enforce authentication for Bluetooth connections. An
Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1
Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below co
The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun
The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers
Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script t
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to by
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started