57,566 vulnerabilities published in 2026
Missing Authorization vulnerability in Marketing Fire LLC LoginWP - Pro allows Accessing Functionality Not Properly Cons
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow p
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 240
A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the appl
Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loa
Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bo
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an i
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a reques
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote atta
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauth
iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote atta
RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated at
Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers
DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information f
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed
The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, a
The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via t
The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check
OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote at
OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote att
fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including
@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of fil
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation Med
The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerabil
Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resultin
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the l
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HT
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment
FLIR Thermal Camera F/FC/PT/D Stream firmware version 8.0.0.64 contains an unauthenticated vulnerability that allows rem
FLIR Thermal Camera F/FC/PT/D firmware version 8.0.0.64 contains hard-coded SSH credentials that cannot be changed throu
FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to acce
INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that ca
Flag Forge is a Capture The Flag (CTF) platform. Versions 2.3.2 and below have a Regular Expression Denial of Service (R
Missing Authorization vulnerability in sizam REHub Framework rehub-framework allows Accessing Functionality Not Properly
Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained b
Missing Authorization vulnerability in loopus WP Attractive Donations System - Easy Stripe & Paypal donations WP_Attract
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Insertion of Sensitive Information Into Sent Data vulnerability in AITpro BulletProof Security bulletproof-security allo
A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create
A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTT
Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbou
An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting com
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started