2026
57,566 vulnerabilities published in 2026
Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection
Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote
Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remot
An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway
Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-a
OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP serv
SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switc
There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products
There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models.
An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-up
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability
Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox E
Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7,
A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts whi
In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: qla2xxx: Perform lockless comma
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso
An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated ne
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allo
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated pa
Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows
WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload mal
In the Linux kernel, the following vulnerability has been resolved: net: hns3: add VLAN id validation before using Cur
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injectio
The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includin
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup res
Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attac
A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A
File upload vulnerability in Omnispace Agora Project before 25.10 allowing authenticated, or under certain conditions al
Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_v
A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminpr
WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editin
ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to create malicious FT
The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scr
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimizatio
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl
OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, whic
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by
Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /gof
A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ.
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /
A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/Config
A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg o
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiF
A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBa
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started