57,566 vulnerabilities published in 2026
An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pr
A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pre
Transient DOS when processing a received frame with an excessively large authentication information element.
A vulnerability in Brocade SANnav before 2.4.0b prints the Password-Based Encryption (PBE) key in plaintext in the syst
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of the first argument of the addImage me
A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the coll
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQue
Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Serio
Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Co
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem
Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Conf
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Hogg The Eve
Missing Authorization vulnerability in WP Chill Passster content-protector allows Exploiting Incorrectly Configured Acce
GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usern
A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The
JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 paramet
pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative fun
Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clo
Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows
A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denia
A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitr
If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such m
The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization i
The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing
An arbitrary file overwrite vulnerability in the file import process of Tarot, Astro & Healing v11.4.0 allows attackers
A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password
GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing /
OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allow
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Pri
IBM Concert 1.0.0 through 2.1.0 is vulnerable to HTTP header injection, caused by improper validation of input by the HO
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mas
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users
IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM
Tanium addressed an incorrect default permissions vulnerability in Performance.
Tanium addressed an incorrect default permissions vulnerability in Patch.
Tanium addressed an incorrect default permissions vulnerability in Partner Integration.
Tanium addressed an incorrect default permissions vulnerability in Discover.
Tanium addressed an incorrect default permissions vulnerability in Comply.
Tanium addressed an incorrect default permissions vulnerability in Benchmark.
Tanium addressed an incorrect default permissions vulnerability in Enforce.
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an unauthorized attac
UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started