57,566 vulnerabilities published in 2026
METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not requi
METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not requi
An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.
Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers t
An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf
DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write acces
ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configu
Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by ov
Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structur
Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execut
Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attac
Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code duri
PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vu
set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability e
Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access contro
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. Th
The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having a
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E
Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H
CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds p
newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisi
webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly han
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
navigation2 is a ROS 2 Navigation Framework and System. In 1.3.11 and earlier, a critical heap out-of-bounds write vulne
Airleader Master versions 6.381 and prior allow for file uploads without restriction to multiple webpages running maxim
Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code b
FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwritin
Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote atta
OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by m
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu
Hyland OnBase contains an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workf
Milvus is an open-source vector database built for generative AI applications. Prior to 2.5.27 and 2.6.10, Milvus expose
Calero VeraSMART versions prior to 2022 R1 expose an unauthenticated .NET Remoting HTTP service on TCP port 8001. The se
Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured for the VeraSMART web app
A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through
Known is a social publishing platform. Prior to 1.6.3, a Critical Broken Authentication vulnerability exists in Known 1.
The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension
The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi
eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after
A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file
Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the sys
Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id fun
Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that
The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotel
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of s
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A
ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started