57,566 vulnerabilities published in 2026
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names,
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_she
Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` whi
The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.22.FInal, the codec-ohttp im
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior
OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site s
The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a
In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 throug
An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attack
A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticat
The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization chec
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0
HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF)
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vu
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` functio
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper se
A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of
A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Ser
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file upl
A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and A
On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensit
A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device
A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficie
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled
An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper han
This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController compo
Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such a
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a c
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutra
MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potentia
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sa
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError
SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/u
Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, whi
Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on fold
Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F
Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks
Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in
Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w
Backend users were able to move records to a different page without having edit permissions on the source page. This iss
Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started