57,566 vulnerabilities published in 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter
A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the
A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The
A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the comp
A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file
Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access c
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S
A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to con
The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as e
The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions
Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command executi
Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS te
WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the Y
The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_m
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerab
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authentic
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remot
A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attack
An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggeri
An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vu
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS
A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Su
nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nn
Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started