57,566 vulnerabilities published in 2026
File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng
Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests
RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-
Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The a
Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint tha
Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote cod
Denver SHC-150 Smart Wifi Camera contains a hardcoded telnet credential vulnerability that allows unauthenticated attack
NoteBurner 2.35 contains a buffer overflow vulnerability in the license code input field that allows attackers to crash
GravCMS 1.10.7 contains an unauthenticated vulnerability that allows remote attackers to write arbitrary YAML configurat
Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may al
Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may all
Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may all
Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an
Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may
Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an at
Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allo
Delta Electronics DIAView has multiple vulnerabilities.
Delta Electronics DIAView has multiple vulnerabilities.
Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to r
The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6
The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 thro
A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/set
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_plan
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer over
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer over
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer over
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursor
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leav
MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.13.2, unauthent
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a netw
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the content
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoo
PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allowi
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a
A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.
An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitra
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr
An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Su
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege e
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell com
Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands thro
DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote a
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started