57,566 vulnerabilities published in 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPre
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / Stell
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descripti
Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0
CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers
CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces
Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que
Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL que
No-Cms 1.0 contains an SQL injection vulnerability in the order_by parameter of the manage_privilege export endpoint tha
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Acco
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Porta
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows
Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service
Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an In
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key
Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys
GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial c
The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged n
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.1
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL an
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom ren
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a ma
Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that a
In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access
Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user ho
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authent
Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker t
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br
A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Run
Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitra
In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_
In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one(
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent networ
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when user
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio a
libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25
A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was a
A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started