57,566 vulnerabilities published in 2026
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command
DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up
mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc
The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrator
A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe
Memory Corruption when processing display command line information due to improper initialization of a variable.
Memory corruption while processing fastboot OEM commands.
Memory corruption while processing fastboot commands with invalid input.
Memory corruption while processing fastboot commands with improperly formatted input.
Memory Corruption when processing fastboot commands to set display mode.
There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attacker may obtain admini
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are pro
A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the comp
A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of t
A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/
A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Serv
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, whe
Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that a
Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting
The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vuln
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, a
WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attac
Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unval
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote aut
md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: thr
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allow
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) al
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, al
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and
The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vu
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Sc
A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file
WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malici
WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthen
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started