57,566 vulnerabilities published in 2026
A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by thi
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unkn
A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the
A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /socia
Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu
A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers
A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted elem
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /i
A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown function
A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown funct
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affect
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class o
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of t
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unkno
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option f
In the Linux kernel, the following vulnerability has been resolved: ptp: ptp_s390: Add missing facility check Only reg
In the Linux kernel, the following vulnerability has been resolved: media: amlogic-c3: Add validations for ae and awb c
In the Linux kernel, the following vulnerability has been resolved: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_
In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_au
Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executab
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, s
Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Proc
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands wit
Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could all
A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unkn
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when install
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path T
The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interface
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authenticatio
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the
A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of t
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAn
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the fil
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file Fi
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started