57,566 vulnerabilities published in 2026
UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the tel
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parame
CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that al
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management
Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attacker
Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attacke
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arb
MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execu
ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to e
MajorDoMo (aka Major Domestic Module) allows unauthenticated remote code execution via the admin panel's PHP console fea
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated remote code execution through supply chain compro
A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file
The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0.
The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3
The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re
The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.
The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints b
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.T
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This
An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server
Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Intern
Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd.
The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Ex
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve server-side request forgery (SSRF) th
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve remote code execution through the arg
In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL
In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These
RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded ins
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, a configuration injection issue in the Docker tool sand
Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis C
Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically impo
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc
Deserialization of Untrusted Data vulnerability in LoftOcean PatioTime patiotime allows Object Injection.This issue affe
Deserialization of Untrusted Data vulnerability in BoldThemes Nestin nestin allows Object Injection.This issue affects N
Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This iss
Deserialization of Untrusted Data vulnerability in BoldThemes Ippsum ippsum allows Object Injection.This issue affects I
Deserialization of Untrusted Data vulnerability in ThemeGoods PhotoMe photome allows Object Injection.This issue affects
Deserialization of Untrusted Data vulnerability in Jthemes Prestige prestige allows Object Injection.This issue affects
Deserialization of Untrusted Data vulnerability in ThemeGoods Capella capella allows Object Injection.This issue affects
Deserialization of Untrusted Data vulnerability in AncoraThemes KindlyCare kindlycare allows Object Injection.This issue
Deserialization of Untrusted Data vulnerability in AncoraThemes SevenHills sevenhills allows Object Injection.This issue
Deserialization of Untrusted Data vulnerability in themesflat Themesflat Elementor themesflat-elementor allows Object In
Deserialization of Untrusted Data vulnerability in ThemeREX Extreme Store extremestore allows Object Injection.This issu
Deserialization of Untrusted Data vulnerability in ThemeREX Lorem Ipsum | Books & Media Store lorem-ipsum-books-media-st
A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The applica
Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injecti
The web management interface of the device allows the administrator username and password to be set to blank values. On
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started