57,566 vulnerabilities published in 2026
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes
openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist s
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nat: reject unsupported target famili
A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_req
A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the comp
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the fi
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore i
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Imp
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sh
vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites tha
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar
A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL of the file uapply.cgi of
The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992
NiceGUI is a Python-based UI framework. From versions 2.22.0 to 3.4.1, an unsafe implementation in the pushstate event l
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server
The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_id’
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource'
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) para
The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unau
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parame
Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "
OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a regist
Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulner
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a ne
A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exp
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni
An improper input handling vulnerability exists in the web-based management interface of mobility conductors running eit
Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors run
Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either A
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upl
Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts thr
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server
e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to overrid
The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu
The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto
The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and
The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array a
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can up
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web
Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started