57,566 vulnerabilities published in 2026
Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary
YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerabi
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software In
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Te
The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP
NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitP
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before vers
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before vers
A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458
A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /gof
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb fra
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP
Account users are allowed by default to register templates to be downloaded directly to the primary storage for deployin
The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Requi
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix UAF in le_read_features_co
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SMP: force responder MITM requirements b
In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for handle opening
In the Linux kernel, the following vulnerability has been resolved: nsfs: tighten permission checks for ns iteration io
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on
Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request
A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWif
Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary co
e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation pe
ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows au
Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation
TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbi
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files an
Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP
A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of th
SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_p
OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolat
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configur
OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and confi
Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path whe
EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can su
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 18.7.10 an
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started