57,566 vulnerabilities published in 2026
Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrator
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to intr
A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts
Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerabi
Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerabil
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is c
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability i
Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vul
Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability
Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is cau
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is
Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vuln
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerabil
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerab
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulne
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerabilit
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerabil
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerabi
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerab
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnera
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vu
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnera
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. T
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function.
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerabil
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerab
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerabili
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not bl
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based
The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu
The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with admin
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with admin
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,
The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked func
The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vul
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started