57,566 vulnerabilities published in 2026
Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not val
Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block
Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), a
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor
A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper val
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version
A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the func
A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_Ot
A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_se
A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /
A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /gofo
A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the f
A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/Portal
A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /gofo
A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRU
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assista
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomT
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, Dataset
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluat
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluat
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions
OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authentic
OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to exec
OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticate
STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attacker
A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file
A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file
A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the f
samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only esca
Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap c
Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit h
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary c
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrar
Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentiall
Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside
Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside
Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrar
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code
Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit hea
Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code insid
Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary
Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary cod
Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially explo
Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started