57,566 vulnerabilities published in 2026
An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a cra
A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device
A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access t
An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable S
A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the work
PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteC
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privile
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated
In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i
The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inc
Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The applica
A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed a
Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() functio
The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPres
Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers t
MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remo
The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu
The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update e
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_pa
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 a
DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerab
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection
An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQ
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to
Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attack
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted,
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in
FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScri
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers
SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in proces
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to injec
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to injec
SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious to
Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parame
NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related f
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started