2026
57,566 vulnerabilities published in 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic
Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass
Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users
iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users
A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSave
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is
Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Re
The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in
Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPC
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convince
Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP C
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authe
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
FLIR Thermal Camera FC-S/PT firmware version 8.0.0.64 contains an authenticated OS command injection vulnerability that
SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary throug
llama.cpp is an inference of several LLM models in C/C++. In commits 55d4206c8 and prior, the n_discard parameter is par
Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authenticat
NeuVector supports login authentication through OpenID Connect. However, the TLS verification (which verifies the remote
RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API v
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol
A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol
Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder
Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder
KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and main
A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat
GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the applicat
A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability af
DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exis
A vulnerability was determined in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /gof
A vulnerability was identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formFir
A security flaw has been discovered in UTT 进取 520W 1.7.7-180627. This impacts the function strcpy of the file /goform/Co
A weakness has been identified in UTT 进取 520W 1.7.7-180627. Affected is the function strcpy of the file /goform/APSecuri
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function s
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /gof
Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows P
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started