57,566 vulnerabilities published in 2026
MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML.
virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.29 a
A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially
A lack of proper input validation in the HTTP processing path in TP-Link Archer BE230 v1.2 (web modules) may allow a cra
A server-side injection was possible for a malicious admin to manipulate the application to include a malicious script w
GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the admi
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents
HCL AION is affected by a vulnerability where certain offering configurations may permit execution of potentially harmfu
Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_u
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the componen
UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the form
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtp
UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the form
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formC
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of th
A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a
** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 fi
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutils during recursive o
A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component
Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulne
A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain lim
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_
A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file int
In Mimecast Incydr before 2.6.0, arbitrary file access can occur.
A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c.
Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorize
Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated a
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini
Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected
Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file a
Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Tr
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resou
Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create()
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo
IBM Virtualization Management Interface FW1110.00 through FW1110.30, FW1120.00 through FW1120.00, and FW1060.00 through
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started