57,566 vulnerabilities published in 2026
Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnera
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-R
A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to e
GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remot
Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source P
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u
Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affec
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a cra
The WiFi Extender WDR201A (HW V2.1, FW LFMZX28040922V1.02) implements a broken authentication mechanism in its web manag
A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX
OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows r
SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs D
Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wh
Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n
Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stac
An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functi
OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when reque
Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F
OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Eng
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter compone
Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer over
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allo
Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buf
Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (E
Heap-based buffer overflow in the KCAPI ECC code path of wc_ecc_import_x963_ex() in wolfSSL wolfcrypt allows a remote at
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the md
OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to joi
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an u
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the te
SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability
Fullchain is an umbrella project for deploying a ready-to-use CTF platform. In versions prior to 0.1.1, due to a mis-wr
The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: REST WebServices) and Oracl
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based
The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api
Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explic
SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.
A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allo
This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe
A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vul
A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers c
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started