57,566 vulnerabilities published in 2026
A null pointer dereference vulnerability in the IP settings CGI program of the Zyxel VMG3625-T50B firmware versions thro
A null pointer dereference vulnerability in the Wake-on-LAN CGI program of the Zyxel VMG3625-T50B firmware version throu
Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, t
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to impr
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which
Bitnami Sealed Secrets is vulnerable to a scope-widening attack during the secret rotation (/v1/rotate) flow. The rotati
VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server rout
Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, `posts_nearby` was
A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can vi
The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to, an
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows upl
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?te
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.
Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted
In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an
A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker
A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQ
The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to,
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisti
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows
Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environmen
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa
An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these
An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an
A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal
wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expo
Server-Side Request Forgery (SSRF) vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer allows Server Side Req
Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0
A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at
A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs
Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.9
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, t
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
Kargo manages and automates the promotion of software artifacts. In versions 1.4.0 through 1.6.3, 1.7.0-rc.1 through 1.7
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderato
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,
The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path
Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in ver
Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:pr
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started