57,566 vulnerabilities published in 2026
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipu
On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen
Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn
An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. Th
Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The pass
A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy
The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is t
The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is
The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done
The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality
The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a
The web interface offers a functionality to export the internal SQLite database. After executing the database export, an
Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has on
The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev
The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis
With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or u
With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta
Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The
By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p
The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sendin
Crucial Storage Executive installer versions prior to 11.08.082025.00 contain a DLL preloading vulnerability. During ins
dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present
DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t
QGIS is a free, open source, cross platform geographical information system (GIS) The repository contains a GitHub Actio
Integer Overflow or Wraparound vulnerability in MuntashirAkon AppManager (app/src/main/java/org/apache/commons/compress/
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in anyrtcIO-Community anyRTC-RTMP-
Multiple Buffer Overflows in Admin UI of EZCast Pro II version 1.17478.146 allow attackers to cause a program crash and
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in CardboardPowered cardboard (src
Out-of-bounds Write vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Onig
Out-of-bounds Read vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Onigu
Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerabili
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine
Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in davisking d
Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow
Vulnerability in Ralim IronOS (source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source mod
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlec
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt761
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt760
NULL Pointer Dereference vulnerability in visualfc liteide (liteidex/src/3rdparty/libvterm/src modules). This vulnerabil
Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/bati
Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-f
Integer Overflow or Wraparound vulnerability in RawTherapee (rtengine modules). This vulnerability is associated with pr
An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 l
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb (src/cjson modules). T
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees
NULL Pointer Dereference vulnerability in abcz316 SKRoot-linuxKernelRoot (testRoot/jni/utils modules). This vulnerabilit
Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is as
Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-pl
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in datavane tis (tis-console/src/main/java/com/qlan
Out-of-bounds Write vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started