57,566 vulnerabilities published in 2026
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the sa
Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to ex
Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attacker
Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the pin
B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Str
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to e
Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attacker
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the Mem
10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that
Azure Front Door Elevation of Privilege Vulnerability
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurity
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-auth
Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fi
3DP-MANAGER is an inbound generator for 3x-ui. In version 2.0.1 and prior, the application automatically creates an admi
Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute
Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by
Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code b
Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attacke
WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied userna
The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OP
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-s
An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can
Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attack
User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated remote attacker obtaining
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Info
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the code evaluation en
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The admin authorizatio
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.10, an authentication bypass vuln
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An insecure default configuration in FUXA allo
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. A path traversal vulnerability in FUXA allows
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication b
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to
Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade In
Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0
CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application e
The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitr
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinos
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started