57,566 vulnerabilities published in 2026
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, a timing attack vulnerability in
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability
A vulnerability in the migration script for Brocade SANnav before 3.0 could allow the collection of database sql queries
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AKCE Software Technology R&D Industry and Tr
A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email ser
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote att
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.char
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
RustFS is a distributed object storage system built in Rust. Prior to version alpha.78, IP-based access control can be b
RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive c
An issue was discovered in Samsung Mobile Processor, Wearable Processor and Modem Exynos 980, 990, 850, 1080, 9110, W920
chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verificati
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulner
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ).
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.
VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by send
School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary file
Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to acc
Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve W
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details
Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability
The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API
The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Ap
A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco Roo
In the Linux kernel, the following vulnerability has been resolved: gue: Fix skb memleak with inner IP protocol 0. syz
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1
Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maxim
Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apol
Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configur
jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, spe
Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer o
NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path
Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allow
UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by man
ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers
ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, w
Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violatio
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an e
Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configu
MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started