57,566 vulnerabilities published in 2026
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link featur
XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents.
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `s
Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects C
Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain p
Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-o
Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain poten
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force U
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validati
A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input vali
Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi
A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encrypt
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad
An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package
Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementa
Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azu
Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situa
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and I
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MST
A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (act
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbit
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST bod
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the asynchronous parsing of
A stack-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within a configuration handling c
A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic.
Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ p
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated au
Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated att
An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. I
Juju is an open source application orchestration engine that enables any application operation on any infrastructure at
Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16
Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQ
Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability
Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in in
PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres
A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function del
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi
Memory Corruption when accessing freed memory due to concurrent fence deregistration and signal handling.
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started