57,566 vulnerabilities published in 2026
Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and
A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules.
A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute
In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by i
The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided b
The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a
The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the
Various sensitive information such as passwords and charging card UIDs are written to log files.
The charging station does not require authentication for Bluetooth commands to perform actions. The functionality expose
The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitra
A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint acce
The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Co
Stored Cross-Site Scripting (XSS) vulnerability in the RD Station Conversas chat. The vulnerability resides in the ‘name
Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located
Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload fu
Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validat
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This v
ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attac
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was
HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export
A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user
A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pa
Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can
Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory o
Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory
Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (
A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible deb
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The m
Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowed
Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis
Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Ac
A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u
A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of
A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature valid
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule
Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Cons
A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP un
A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper va
A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to
A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of fi
A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of e
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on
Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started