57,566 vulnerabilities published in 2026
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code in
Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of
Use after free in Video in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who had compromise
Use after free in FileSystem in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially exploit o
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bo
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with cha
WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local
In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of u
The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and includi
The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and
The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitr
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocit
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt
The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat
xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle a
Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary comm
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and execute
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynam
WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in da
FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to N
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti
Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload an
An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause
A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_B
A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoByI
A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPIn
SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in proce
ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attacker
A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromGstDhcpSetSer of the fil
A vulnerability was determined in Tenda F451 1.0.0.7_cn_svn7958. Impacted is the function fromwebExcptypemanFilter of th
A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromSafeClientFilt
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r
Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft
Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a
In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcf
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows n
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started