57,566 vulnerabilities published in 2026
Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src
Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a success
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Intercepti
Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b
Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsin
SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptogra
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patch
An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access t
A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can exe
A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)
HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The functi
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against th
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the ac
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto
Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in
The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled,
SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but ex
Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verifica
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx all
Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause
Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.
Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker wh
Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex
Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scri
Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-
Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro
The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitr
decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' produci
PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support fr
Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. The vulnerability allows a remote,
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time comple
HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an ema
Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to
An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/inde
An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote C
Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographical
KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid
KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functio
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic,
KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started