57,566 vulnerabilities published in 2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, For
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Pr
A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr
The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password f
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account l
vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototyp
HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.0
Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in azerothcore
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.
Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.
Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows a
Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports
VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate
Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to
Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject
code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.
improper pointer arithmetic vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-s
code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid para
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password paramete
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Addres
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnaly
An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may a
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions,
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could
The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows rem
Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers t
YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-
Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process th
`bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar co
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all suppor
BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Han
Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary
Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execu
BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attacker
Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary
A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated a
An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starti
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started