57,566 vulnerabilities published in 2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUX
NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filen
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Comm
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM a
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vuln
Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting
aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by ov
SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the applica
AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using
ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers
Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash th
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrie
WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully vali
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checkl
WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checkl
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports weak cr
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL
An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path tr
C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbit
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerabili
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, video_timer can send client notificati
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, urb_select_interface can free the devi
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, AUDIN format renegotiation frees the a
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample response
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure,
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completion
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an inc
FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a lo
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can p
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthe
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig f
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener acc
Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 an
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs h
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-16 and earlier, the group chat WebSocket at wss:/
Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where admi
SumatraPDF is a multi-format reader for Windows. In 3.5.0 through 3.5.2, SumatraPDF's update mechanism disables TLS host
SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause t
SAP BusinessObjects BI Platform allows an unauthenticated attacker to craft a specific network request to the trusted en
Docpedia developed by Flowring has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject ar
The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin
Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
Null pointer dereference in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker t
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a
Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core
A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started