57,566 vulnerabilities published in 2026
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5,
The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the ‘args’ parameter in all ve
The OpenPix for WooCommerce WordPress plugin through 2.13.3 allows any authenticated user to trigger AJAX actions that r
The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthentic
The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 th
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user ac
A use of out-of-range pointer offset vulnerability has been reported to affect Qsync Central. If a remote attacker gains
An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accoun
An out-of-bounds read vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a re
A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user acc
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th
An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gain
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, th
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, th
A lack of session validation in the web API component of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remot
Insufficient policy enforcement in Frames in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform U
Inappropriate implementation in Animation in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to leak cros
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who c
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinc
BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard wi
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, mac
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7
When connecting to the Solax Cloud MQTT server the username is the "registration number", which is the 10 character stri
The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot module reloading) server d
LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadat
E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard with
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attacker
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 all
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started