57,566 vulnerabilities published in 2026
A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's
To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbi
FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1
Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with ad
Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with ad
In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead
Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using special
Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could cre
Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwar
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service due to in
Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The upda
Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authentic
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration ac
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration ac
An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, th
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan);
Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthent
picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to e
Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site
CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1
Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, users can reset their
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks
vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial us
vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps
8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile
SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta
Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr
Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network
A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3
Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl
An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m
An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p
A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the
Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's
UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti
uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an
UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling
UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte
UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f
UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started